Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| ibm | aix | 4.1.5 |
| sgi | irix | 6.0 |
| ibm | aix | 4.1 |
| sun | sunos | - |
| sun | sunos | 4.1.3 |
| hp | hp-ux | 10.03 |
| tritreal | ted_cde | 4.3 |
| sgi | irix | 6.3 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| ibm | aix | 4.1.1 |
| sgi | irix | 5.2 |
| sun | sunos | 5.0 |
| sun | sunos | 5.2 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| ibm | aix | 4.2.1 |
| sun | sunos | 5.5 |
| hp | hp-ux | 11.00 |
| sun | solaris | 2.6 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.3 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| ibm | aix | 4.1.2 |
| hp | hp-ux | 10.02 |
| sgi | irix | 5.3 |
| ibm | aix | 4.2 |
| sun | sunos | 5.1 |
| sun | sunos | 5.4 |
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.0 |
| sgi | irix | 3.3.2 |
| sgi | irix | 3.2 |
| sco | open_desktop | 5.0 |
| sco | open_desktop | 3.0 |
| caldera | openlinux | 1.0 |
| sco | unixware | 7.0 |
| sgi | irix | 4.0.1t |
| sgi | irix | 3.3.3 |
| sgi | irix | 4.0.5a |
| data_general | dg_ux | 5.4_3.1 |
| sgi | irix | 4.0.5h |
| sgi | irix | 4.0.5_ipr |
| sgi | irix | 5.0.1 |
| sgi | irix | 4.0.2 |
| sgi | irix | 4.0.5e |
| netbsd | netbsd | 1.3 |
| netbsd | netbsd | 1.2.1 |
| sgi | irix | 5.2 |
| sgi | irix | 4.0.4t |
| netbsd | netbsd | 1.1 |
| bsdi | bsd_os | 2.0 |
| sgi | irix | 4.0.5 |
| ibm | aix | 4.2.1 |
| sun | sunos | 5.5 |
| redhat | linux | 4.1 |
| sgi | irix | 4.0 |
| netbsd | netbsd | 1.2 |
| data_general | dg_ux | 5.4_4.1 |
| sun | solaris | 2.5.1 |
| data_general | dg_ux | 5.4_3.0 |
| ibm | aix | 4.1.3 |
| sgi | irix | 4.0.5g |
| sgi | irix | 3.3 |
| ibm | aix | 4.1.2 |
| sgi | irix | 5.3 |
| bsdi | bsd_os | 2.0.1 |
| ibm | aix | 4.2 |
| sgi | irix | 4.0.4b |
| sun | sunos | 5.4 |
| ibm | aix | 4.1.5 |
| nec | asl_ux_4800 | 64 |
| ibm | aix | 4.1 |
| sun | sunos | - |
| isc | bind | 8.1.1 |
| sgi | irix | 4.0.5f |
| sgi | irix | 5.1.1 |
| redhat | linux | 4.0 |
| netbsd | netbsd | 1.3.1 |
| sun | solaris | 2.5 |
| sgi | irix | 3.3.1 |
| sgi | irix | 4.0.5d |
| isc | bind | 8.1 |
| sgi | irix | 6.3 |
| ibm | aix | 4.1.4 |
| sgi | irix | 5.0 |
| sun | sunos | 5.5.1 |
| ibm | aix | 4.1.1 |
| sgi | irix | 4.0.4 |
| redhat | linux | 4.2 |
| redhat | linux | 5.0 |
| sun | sunos | 5.3 |
| sgi | irix | 4.0.1 |
| sgi | irix | 4.0.5_iop |
| sco | unixware | 2.1 |
| sun | solaris | 2.6 |
| netbsd | netbsd | 1.0 |
| data_general | dg_ux | 5.4_4.11 |
| bsdi | bsd_os | 2.1 |
| ibm | aix | 4.3 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| sgi | irix | 5.1 |
| sgi | irix | 4.0.3 |
| isc | bind | 4.9.6 |
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| data_general | dg_ux | y2k_patchr4.11mu05 |
| data_general | dg_ux | y2k_patchr4.20mu01 |
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| sco | unixware | 7.0 |
| netbsd | netbsd | 1.3.1 |
| data_general | dg_ux | y2k_patchr4.20mu02 |
| nec | asl_ux_4800 | 11 |
| sco | unix | 3.2v4 |
| nec | asl_ux_4800 | 13 |
| sun | sunos | 5.5.1 |
| netbsd | netbsd | 1.3 |
| sco | openserver | 5.0 |
| redhat | linux | 4.2 |
| redhat | linux | 5.0 |
| sun | sunos | 5.3 |
| isc | bind | 4.9 |
| sun | sunos | 5.5 |
| sco | unixware | 2.1 |
| data_general | dg_ux | y2k_patchr4.20mu03 |
| ibm | aix | 4.3 |
| sun | sunos | 5.6 |
| isc | bind | 8 |
| ibm | aix | 4.2 |
| data_general | dg_ux | y2k_patchr4.12mu03 |
| sun | sunos | 5.4 |
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.4 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L | 2.8 | 2.5 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,CWE-1067,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| data_general | dg_ux | y2k_patchr4.11mu05 |
| data_general | dg_ux | y2k_patchr4.20mu01 |
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| sco | unixware | 7.0 |
| netbsd | netbsd | 1.3.1 |
| data_general | dg_ux | y2k_patchr4.20mu02 |
| nec | asl_ux_4800 | 11 |
| sco | unix | 3.2v4 |
| nec | asl_ux_4800 | 13 |
| sun | sunos | 5.5.1 |
| netbsd | netbsd | 1.3 |
| sco | openserver | 5.0 |
| redhat | linux | 4.2 |
| redhat | linux | 5.0 |
| sun | sunos | 5.3 |
| isc | bind | 4.9 |
| sun | sunos | 5.5 |
| sco | unixware | 2.1 |
| data_general | dg_ux | y2k_patchr4.20mu03 |
| ibm | aix | 4.3 |
| sun | sunos | 5.6 |
| isc | bind | 8 |
| ibm | aix | 4.2 |
| data_general | dg_ux | y2k_patchr4.12mu03 |
| sun | sunos | 5.4 |
Unauthorized privileged access or denial of service via dtappgather program in CDE.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | vvos | 10.24 |
| hp | hp-ux | 10.10 |
| cde | cde | 1.2 |
| cde | cde | 1.01_x86 |
| ibm | aix | 4.1 |
| hp | hp-ux | 11.00 |
| cde | cde | 1.2_x86 |
| cde | cde | 1.02_x86 |
| hp | hp-ux | 10.20 |
| ibm | aix | 4.3 |
| cde | cde | 1.01 |
| ibm | aix | 4.2 |
| cde | cde | 1.02 |
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 1.1 |
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| freebsd | freebsd | 1.0 |
| sco | openserver | 5.0.4 |
| freebsd | freebsd | 2.1.0 |
| siemens | reliant_unix | * |
| freebsd | freebsd | 2.1.7 |
| sun | sunos | 5.5.1 |
| netbsd | netbsd | 1.2.1 |
| netbsd | netbsd | 1.1 |
| freebsd | freebsd | 2.0 |
| gnu | inet | 5.01 |
| sun | sunos | 5.3 |
| sun | sunos | 5.5 |
| sco | unixware | 2.1 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| netbsd | netbsd | 1.0 |
| netbsd | netbsd | 1.2 |
| freebsd | freebsd | 1.2 |
| gnu | inet | 6.01 |
| ibm | aix | 4.3 |
| washington_university | wu-ftpd | 2.4 |
| gnu | inet | 6.02 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| caldera | openlinux | 1.2 |
| sun | sunos | 5.4 |
Buffer overflow in statd allows root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 5.2 |
| ibm | aix | 4.1 |
| sun | sunos | 5.5 |
| sgi | irix | 5.1.1 |
| sun | solaris | 2.5 |
| sun | solaris | 2.5.1 |
| sun | solaris | 2.4 |
| sgi | irix | 5.0.1 |
| sgi | irix | 5.3 |
| ibm | aix | 3.2 |
| sgi | irix | 5.1 |
| sgi | irix | 5.0 |
| sun | sunos | 5.5.1 |
| sun | sunos | 5.4 |
Delete or create a file via rpc.statd, due to invalid information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sco | openserver | 5.0 |
| ncr | mp-ras | 3.0 |
| sco | unixware | 2 |
| sco | open_desktop | 3 |
| sun | sunos | 5.3 |
| ibm | aix | 4.1 |
| sun | sunos | 5.5 |
| data_general | dg_ux | 4.11 |
| sun | sunos | 4.1.3 |
| sco | openserver | 3.0 |
| sun | sunos | 4.1.4 |
| nighthawk | cx_ux | * |
| sco | open_desktop | 2 |
| ncr | mp-ras | 2.03 |
| sgi | irix | 6.1 |
| ibm | aix | 3.2 |
| nighthawk | powerux | * |
| sun | sunos | 5.4 |
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,CWE-125,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| ibm | aix | 4.1.5 |
| sgi | irix | 6.0 |
| ibm | aix | 4.1 |
| ibm | aix | 3.2.5 |
| sgi | irix | 5.1.1 |
| freebsd | freebsd | 2.1.0 |
| hp | hp-ux | 10.00 |
| sgi | irix | 5.0.1 |
| freebsd | freebsd | 2.0.5 |
| sgi | irix | 6.3 |
| ibm | aix | 4.1.4 |
| sun | solaris | 4.1.3 |
| sgi | irix | 5.0 |
| ibm | aix | 4.1.1 |
| ibm | aix | 3.2.4 |
| sgi | irix | 5.2 |
| sun | sunos | 5.0 |
| sgi | irix | 6.0.1 |
| ibm | aix | 3.1 |
| freebsd | freebsd | 2.0 |
| sun | sunos | 5.2 |
| sun | sunos | 5.3 |
| sun | sunos | 4.1.3u1 |
| bsdi | bsd_os | 1.1 |
| sun | sunos | 4.1.2 |
| ibm | aix | 4.1.3 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| ibm | aix | 4.1.2 |
| sgi | irix | 5.3 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| sun | sunos | 5.1 |
| sgi | irix | 5.1 |
| sun | sunos | 4.1.1 |
| sun | sunos | 5.4 |
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| sun | sunos | - |
| sco | tcp_ip | 1.2.0 |
| sun | sunos | 4.1.3 |
| sco | internet_faststart | 1.0 |
| freebsd | freebsd | 2.1.0 |
| freebsd | freebsd | 2.2 |
| freebsd | freebsd | 2.0.5 |
| sun | sunos | 5.5.1 |
| sco | open_desktop | 2.0 |
| sco | openserver | 5.0 |
| freebsd | freebsd | 2.0 |
| sun | sunos | 5.3 |
| inet | inet | 6.01 |
| sun | sunos | 5.5 |
| sco | unixware | 2.1 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| sco | openserver | 2.0 |
| inet | inet | 5.01 |
| sco | openserver | 5.0.2 |
| sco | tcp_ip | 1.2.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| sco | unixware | 2.0 |
| bsdi | bsd_os | * |
| sun | sunos | 5.4 |
DNS cache poisoning via BIND, by predictable query IDs.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sco | openserver | 5.0 |
| nec | asl_ux_4800 | 64 |
| sun | sunos | 5.3 |
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| sun | sunos | - |
| nec | ews-ux_v | 4.2mp |
| sun | sunos | 5.5 |
| isc | bind | 4.9.5 |
| sco | unixware | 2.1 |
| sun | solaris | 2.6 |
| bsdi | bsd_os | 3.0 |
| sun | solaris | 2.5 |
| sun | solaris | 2.5.1 |
| nec | ews-ux_v | 4.2 |
| nec | up-ux_v | 4.2mp |
| bsdi | bsd_os | 2.1 |
| sun | solaris | 2.4 |
| sco | unix | 3.2v4 |
| isc | bind | 8.1 |
| ibm | aix | 4.2 |
| sun | sunos | 5.5.1 |
| sun | sunos | 5.4 |
Command execution in Sun systems via buffer overflow in the at program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | * |
| sco | openserver | 5.0 |
| ibm | aix | * |
| ncr | mp-ras | 3.0 |
| sun | sunos | 5.3 |
| sco | open_desktop | 3.0 |
| sun | sunos | 5.5 |
| sco | unixware | 2.1 |
| sco | openserver | 3.0 |
| sco | unixware | 3.2v4 |
| sun | sunos | 5.5.1 |
| sun | sunos | 5.4 |
Buffer overflow in xlock program allows local users to execute commands as root.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 2.5 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| sgi | irix | 6.0 |
| hp | hp-ux | 10.10 |
| debian | debian_linux | 0.93 |
| ibm | aix | 4.1 |
| data_general | dg_ux | 7.0 |
| debian | debian_linux | 1.3 |
| sgi | irix | 5.1.1 |
| hp | hp-ux | 10.34 |
| data_general | dg_ux | 1.0 |
| debian | debian_linux | 1.2 |
| sun | solaris | 2.5 |
| hp | hp-ux | 10.30 |
| hp | hp-ux | 10.00 |
| sgi | irix | 5.0.1 |
| sgi | irix | 6.3 |
| data_general | dg_ux | 4.0 |
| sgi | irix | 5.0 |
| sun | sunos | 5.5.1 |
| sgi | irix | 5.2 |
| sgi | irix | 6.0.1 |
| hp | hp-ux | 10.16 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| hp | hp-ux | 10.24 |
| data_general | dg_ux | 3.0 |
| sun | sunos | 5.5 |
| data_general | dg_ux | 6.0 |
| debian | debian_linux | 1.1 |
| sun | solaris | 2.5.1 |
| bsdi | bsd_os | 2.1 |
| sun | solaris | 2.4 |
| data_general | dg_ux | 2.0 |
| hp | hp-ux | 10.20 |
| sgi | irix | 6.1 |
| sgi | irix | 5.3 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| hp | hp-ux | 10.08 |
| sgi | irix | 5.1 |
| sun | sunos | 5.4 |
| data_general | dg_ux | 5.0 |
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| sgi | irix | 6.0 |
| hp | hp-ux | 10.10 |
| hp | hp-ux | 9.00 |
| nec | asl_ux_4800 | 64 |
| ibm | aix | 4.1 |
| nec | ews-ux_v | 4.2mp |
| sun | sunos | 4.1.3 |
| hp | hp-ux | 10.34 |
| sun | solaris | 2.5 |
| hp | hp-ux | 10.30 |
| hp | hp-ux | 10.00 |
| sgi | irix | 6.3 |
| sgi | irix | 5.0 |
| sun | sunos | 5.5.1 |
| bsdi | bsd_os | 2.0 |
| hp | hp-ux | 10.16 |
| freebsd | freebsd | 2.0 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| hp | hp-ux | 10.24 |
| hp | hp-ux | 9.10 |
| sun | sunos | 5.5 |
| sgi | irix | 4.0 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| sun | solaris | 2.5.1 |
| nec | ews-ux_v | 4.2 |
| hp | hp-ux | 9.01 |
| freebsd | freebsd | 1.1.5.1 |
| nec | up-ux_v | 4.2mp |
| bsdi | bsd_os | 2.1 |
| sun | solaris | 2.4 |
| hp | hp-ux | 10.20 |
| hp | hp-ux | 10.09 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| sgi | irix | 5.3 |
| ibm | aix | 3.2 |
| bsdi | bsd_os | 2.0.1 |
| ibm | aix | 4.2 |
| hp | hp-ux | 10.08 |
| sun | sunos | 5.4 |
Buffer overflow in NLS (Natural Language Service).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1 |
| ibm | aix | 3.2.5 |
| redhat | linux | 4.0 |
| gnu | libc | 5.0.9 |
| slackware | slackware_linux | 3.1 |
| cray | unicos | 9.2 |
| cray | unicos | 1.5 |
| ibm | aix | 4.2 |
| gnu | libc | 5.2.18 |
| gnu | libc | 5.3.12 |
| cray | unicos | 9.0 |
| cray | unicos_max | 1.3 |
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| bsdi | bsd_os | 2.1 |
| redhat | linux | 2.0 |
| ibm | aix | 4.2.1 |
| university_of_washington | pop | 3 |
| caldera | openlinux | 1.0 |
| university_of_washington | imap | 4 |
| redhat | linux | 4.0 |
| bsdi | bsd_os | 3.0 |
Buffer overflow of rlogin program using TERM environmental variable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| oracle | solaris | 8 |
| hp | hp-ux | 10.10 |
| debian | debian_linux | 0.93 |
| ibm | aix | 4.1 |
| hp | hp-ux | 10.34 |
| hp | hp-ux | 10.30 |
| freebsd | freebsd | 2.1.0 |
| hp | hp-ux | 10.00 |
| oracle | solaris | 2.6 |
| freebsd | freebsd | 2.0.5 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| ibm | aix | 4.1.1 |
| digital | ultrix | - |
| oracle | solaris | - |
| netbsd | netbsd | 1.1 |
| bsdi | bsd_os | 2.0 |
| hp | hp-ux | 10.16 |
| freebsd | freebsd | 2.0 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| hp | hp-ux | 10.24 |
| sun | sunos | 5.5 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| netbsd | netbsd | 1.0 |
| bsdi | bsd_os | 1.1 |
| oracle | solaris | 7.0 |
| freebsd | freebsd | 1.1.5.1 |
| bsdi | bsd_os | 2.1 |
| next | nextstep | - |
| ibm | aix | 4.1.3 |
| hp | hp-ux | 10.20 |
| hp | hp-ux | 10.09 |
| ibm | aix | 4.1.2 |
| ibm | aix | 3.2 |
| bsdi | bsd_os | 2.0.1 |
| hp | hp-ux | 10.08 |
| freebsd | freebsd | 2.1.5 |
| oracle | solaris | 2.5.1 |
| sun | sunos | 5.4 |
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.1 |
| ibm | aix | 4.1 |
| nec | up-ux_v | * |
| ibm | aix | 4.2 |
| nec | ews-ux_v | * |
| debian | netkit | 0.07 |
| nec | asl_ux_4800 | * |
Buffer overflows in Sun libnsl allow root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | sunos | 5.2 |
| sun | sunos | 5.3 |
| ibm | aix | 4.2.1 |
| sun | sunos | - |
| sun | sunos | 5.5 |
| sun | solaris | 2.6 |
| sun | solaris | 2.5 |
| sun | solaris | 2.5.1 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| sun | solaris | 2.4 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2 |
| sun | sunos | 5.5.1 |
| sun | sunos | 5.4 |
Vacation program allows command execution by remote users through a sendmail command.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 6.2 |
| hp | hp-ux | 9 |
| sun | sunos | * |
| ibm | aix | * |
| sun | solaris | * |
| hp | hp-ux | 10.00 |
| eric_allman | vacation | * |
| hp | hp-ux | 10.09 |
| hp | vvos | * |
| hp | hp-ux | 10.24 |
Buffer overflow in AIX lquerylv program gives root access to local users.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 3.2.5 |
| ibm | aix | 4.1.1 |
Buffer overflow in AIX xdat gives root access to local users.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 6.2 |
| ncr | mp-ras | 3.0 |
| sun | sunos | 4.1 |
| ibm | aix | 4.1 |
| ncr | mp-ras | 3.01 |
| sun | sunos | 5.5 |
| next | nextstep | * |
| sco | unixware | 2.1 |
| ncr | mp-ras | 2.03 |
| sgi | irix | 5.3 |
| nec | up-ux_v | * |
| sco | openserver | 5 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| hp | hp-ux | * |
| bsdi | bsd_os | * |
| sun | sunos | 5.4 |
Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 6.2 |
| ibm | aix | 4.2 |
| netbsd | netbsd | 2.0.4 |
AIX routed allows remote users to modify sensitive files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
| ibm | aix | 4.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Buffer overflow in AIX rcp command allows local users to obtain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
Buffer overflow in AIX writesrv command allows local users to obtain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.2.1 |
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
AIX piodmgrsu command allows local users to gain additional group privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| hp | hp-ux | 10.10 |
| hp | hp-ux | 9.08 |
| hp | hp-ux | 9.00 |
| hp | hp-ux | 9.09 |
| ibm | aix | 4.1 |
| sun | sunos | - |
| ibm | aix | 3.2.5 |
| sun | solaris | 2.5 |
| hp | hp-ux | 9.07 |
| hp | hp-ux | 10.00 |
| hp | hp-ux | 9.04 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| ibm | aix | 4.1.1 |
| ibm | aix | 3.2.4 |
| hp | hp-ux | 10.16 |
| sun | sunos | 5.3 |
| hp | hp-ux | 9.05 |
| hp | hp-ux | 10.24 |
| ibm | aix | 4.2.1 |
| hp | hp-ux | 9.10 |
| sun | sunos | 5.5 |
| hp | hp-ux | 9.06 |
| hp | hp-ux | 11.00 |
| sun | solaris | 2.6 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| sun | solaris | 2.5.1 |
| hp | hp-ux | 9.01 |
| sun | solaris | 2.4 |
| ibm | aix | 4.1.3 |
| hp | hp-ux | 9.03 |
| hp | hp-ux | 10.20 |
| ibm | aix | 4.1.2 |
| sun | sunos | 4.1.3c |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| sun | sunos | 5.4 |
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| bsdi | bsd_os | 2.0 |
| convex | convexos | 10.1 |
| cray | unicos | 8.3 |
| sun | sunos | 5.3 |
| ibm | aix | 4.1 |
| convex | convexos | 10.2 |
| convex | convexos | 11.1 |
| sun | sunos | 4.1.3 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| cray | unicos | 8.0 |
| convex | spp-ux | 3 |
| sun | solaris | 2.4 |
| ibm | aix | 3.2 |
| bsdi | bsd_os | 2.0.1 |
| convex | convexos | 11.0 |
| cray | unicos | 9.0 |
| sun | sunos | 5.4 |
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
RIP v1 is susceptible to spoofing.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
| ibm | aix | 4.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
Buffer overflow in AIX dtterm program for the CDE.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cde | cde | * |
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
Some implementations of rlogin allow root access if given a -froot parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-88,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
| ibm | aix | 3.2.5 |
AIX bugfiler program allows local users to gain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
| ibm | aix | 3.2.5 |
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sng | 2.2 |
| ibm | sng | 2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
| ibm | aix | 3.2.5 |
AIX passwd allows local users to gain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
AIX infod allows local users to gain root access through an X display.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
| ibm | aix | 4.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
Buffer overflow in AIX lchangelv gives root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sco | openserver | 5.0 |
| ibm | sng | 2.2 |
| digital | osf_1 | 1.3.3 |
| ibm | aix | 4.1 |
| sco | open_desktop | 3.0 |
| sun | sunos | 5.5 |
| ibm | sng | * |
| sco | internet_faststart | 1.0 |
| linux | linux_kernel | 1.3.0 |
| sco | openserver | 5.0.2 |
| sco | tcp_ip | 1.2.1 |
| sco | internet_faststart | 1.1 |
| ibm | sng | 2.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| sun | sunos | 5.5.1 |
| linux | linux_kernel | 2.0 |
| sun | sunos | 5.4 |
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | hp-ux | 10.10 |
| eric_allman | sendmail | 8.8.1 |
| eric_allman | sendmail | 8.8.2 |
| ibm | aix | 4.1 |
| sun | solaris | 2.5 |
| sco | internet_faststart | 1.0 |
| eric_allman | sendmail | 8.8 |
| hp | hp-ux | 10.00 |
| freebsd | freebsd | 2.1.6.1 |
| sun | sunos | 5.5.1 |
| sco | openserver | 5.0 |
| hp | hp-ux | 10.16 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| sun | sunos | 5.5 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| sun | solaris | 2.5.1 |
| bsdi | bsd_os | 2.1 |
| eric_allman | sendmail | 8.8.3 |
| sun | solaris | 2.4 |
| hp | hp-ux | 10.20 |
| sco | openserver | 5.0.2 |
| freebsd | freebsd | 2.1.6 |
| sco | internet_faststart | 1.1 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| freebsd | freebsd | 2.1.5 |
| sun | sunos | 5.4 |
Local users can start Sendmail in daemon mode and gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| eric_allman | sendmail | 8.7 |
| hp | hp-ux | 10.10 |
| eric_allman | sendmail | 8.8.1 |
| eric_allman | sendmail | 8.8.2 |
| hp | hp-ux | 10.01 |
| caldera | network_desktop | 1.0 |
| redhat | linux | 4.0 |
| bsdi | bsd_os | 2.1 |
| eric_allman | sendmail | 8.8 |
| hp | hp-ux | 10.00 |
| hp | hp-ux | 10.20 |
| freebsd | freebsd | 2.1.6 |
| ibm | aix | 4.2 |
| freebsd | freebsd | 2.1.5 |
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sco | openserver | 5.0 |
| hp | hp-ux | 10.10 |
| eric_allman | sendmail | 8.7.1 |
| hp | hp-ux | 10.01 |
| ibm | aix | 4.1 |
| eric_allman | sendmail | 8.7.4 |
| eric_allman | sendmail | 8.7.5 |
| eric_allman | sendmail | 8.7.3 |
| bsdi | bsd_os | 2.1 |
| sco | internet_faststart | 1.0 |
| hp | hp-ux | 10.20 |
| digital | osf_1 | 1.3.2 |
| sco | openserver | 5.0.2 |
| eric_allman | sendmail | 8.6 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| eric_allman | sendmail | 8.7.2 |
| freebsd | freebsd | 2.1.5 |
| redhat | linux | 3.0.3 |
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | hp-ux | 9 |
| freebsd | freebsd | 2.0 |
| ibm | aix | 4 |
| linux | linux_kernel | 1.2.0 |
| nec | ews-ux_v | 4.2mp |
| nec | asl_ux_4800 | * |
| ibm | aix | 3.2.5 |
| hp | hp-ux | 10 |
| nec | ews-ux_v | 4.2 |
| nec | up-ux_v | 4.2mp |
| digital | osf_1 | 1.3 |
| freebsd | freebsd | 2.1.0 |
| apple | a_ux | 3.1.1 |
| hp | hp-ux | 8 |
| freebsd | freebsd | 2.0.5 |
| linux | linux_kernel | 2.0 |
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 5.2 |
| sgi | irix | 4 |
| sgi | irix | 3 |
| ibm | aix | 4.1 |
| nec | up-ux_v | * |
| ibm | aix | 3.2 |
| sgi | irix | 5.1 |
| nec | ews-ux_v | * |
| sgi | irix | 5.0 |
| nec | asl_ux_4800 | * |
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| microsoft | exchange_server | 4.0 |
| ibm | lotus_domino_mail_server | * |
| microsoft | exchange_server | 5.0 |
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | sunos | 5.7 |
| sun | sunos | 5.8 |
| redhat | linux | 6.0 |
| ibm | aix | 4 |
| hp | hp-ux | 11 |
| sun | sunos | 5.5.1 |
| sun | solaris | 2.6 |
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 1.3 |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
| ibm | aix | 2.2.1 |
| ibm | aix | 1.2.1 |
AIX Licensed Program Product performance tools allow local users to gain root access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 3.2.5 |
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sng | 2.2 |
| freebsd | freebsd | 2.0 |
| sco | open_desktop | 3 |
| freebsd | freebsd | 1.1 |
| ibm | aix | 4.1 |
| freebsd | freebsd | 1.0 |
| freebsd | freebsd | 1.2 |
| sun | sunos | * |
| freebsd | freebsd | 1.1.5.1 |
| sco | internet_faststart | 1.0 |
| sco | internet_faststart | 1.1 |
| ibm | sng | 2.1 |
| freebsd | freebsd | 2.0.5 |
| sco | openserver | 5 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 4.5 |
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 2.2.4 |
| digital | unix | 4.0d |
| sun | sunos | - |
| ibm | aix | 3.2.5 |
| linux | linux_kernel | 2.1 |
| sun | solaris | 2.5 |
| digital | unix | 4.0a |
| freebsd | freebsd | 2.2.2 |
| digital | unix | 4.0c |
| freebsd | freebsd | 2.1.0 |
| digital | unix | 4.0b |
| freebsd | freebsd | 2.0.5 |
| sun | sunos | 5.5.1 |
| linux | linux_kernel | 2.0 |
| ibm | aix | 3.2.4 |
| ibm | aix | 3.1 |
| digital | unix | 4.0 |
| sun | sunos | 5.5 |
| hp | hp-ux | 11.00 |
| digital | unix | 3.2g |
| freebsd | freebsd | 2.1.7.1 |
| sun | solaris | 2.6 |
| netbsd | netbsd | 1.2 |
| sun | solaris | 2.5.1 |
| freebsd | freebsd | 1.1.5.1 |
| sun | solaris | 2.4 |
| hp | hp-ux | 10.20 |
| freebsd | freebsd | 2.2.3 |
| freebsd | freebsd | 2.1.6 |
| ibm | aix | 3.2 |
| freebsd | freebsd | 2.1.5 |
| sun | sunos | 5.4 |
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.0 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | 2.5 | 1.4 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,NVD-CWE-noinfo,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os2 | - |
| apple | mac_os_x | - |
| linux | linux_kernel | - |
| novell | netware | - |
| ibm | aix | - |
| cisco | ios | - |
| windriver | bsdos | - |
| sgi | irix | - |
| apple | macos | - |
| sco | sco_unix | - |
| hp | tru64 | - |
| microsoft | windows | - |
| hp | hp-ux | - |
| oracle | solaris | - |
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
The rwho/rwhod service is running, which exposes machine status and user information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 6.2 |
| ibm | aix | 4.2 |
| linux | linux_kernel | 2.6.20.1 |
| netbsd | netbsd | 2.0.4 |
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | solaris | 7.0 |
| ibm | aix | 4.1.5 |
| cde | cde | 1.2 |
| cde | cde | 2.0 |
| digital | unix | 4.0d |
| ibm | aix | 4.1 |
| sun | sunos | - |
| cde | cde | 1.0.1 |
| cde | cde | 1.1 |
| sun | solaris | 2.5 |
| sun | sunos | 5.7 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| cde | cde | 1.0.2 |
| ibm | aix | 4.1.1 |
| cde | cde | 2.1 |
| sun | sunos | 5.3 |
| ibm | aix | 4.2.1 |
| sun | sunos | 5.5 |
| sun | solaris | 2.6 |
| sun | sunos | 4.1.3u1 |
| sun | sunos | 4.1.4 |
| sun | solaris | 2.5.1 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| sun | solaris | 2.4 |
| ibm | aix | 4.1.3 |
| digital | unix | 4.0f |
| ibm | aix | 4.3 |
| ibm | aix | 4.1.2 |
| cde | cde | 2.120 |
| ibm | aix | 4.2 |
| sun | sunos | 5.4 |
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | solaris | 7.0 |
| ibm | aix | 4.1.5 |
| cde | cde | 1.2 |
| cde | cde | 2.0 |
| digital | unix | 4.0d |
| ibm | aix | 4.1 |
| cde | cde | 1.0.1 |
| cde | cde | 1.1 |
| sun | sunos | 5.7 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| cde | cde | 1.0.2 |
| ibm | aix | 4.1.1 |
| digital | unix | 4.0e |
| cde | cde | 2.1 |
| ibm | aix | 4.2.1 |
| sun | sunos | 5.5 |
| sun | solaris | 2.6 |
| sun | solaris | 2.5.1 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| sun | solaris | 2.4 |
| ibm | aix | 4.1.3 |
| digital | unix | 4.0f |
| ibm | aix | 4.3 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| sun | sunos | 5.4 |
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | hp-ux | 10 |
| ibm | aix | 4 |
| hp | hp-ux | 11 |
| sco | unixware | 7 |
Denial of service in AIX ptrace system call allows local users to crash the system.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
| ibm | aix | 4.2 |
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | gina | 1.0 |
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 4.6 |
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
| ibm | aix | 2.2.1 |
| ibm | aix | 3.2.5 |
Buffer overflow in AIX ftpd in the libc library.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3 |
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix_enetwork_firewall | 3.2 |
| ibm | aix_enetwork_firewall | 3.3 |
Denial of service in BIND named via malformed SIG records.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | sunos | 5.7 |
| sco | unixware | 2 |
| ibm | aix | 4.3 |
| sco | unixware | 7 |
| sco | openserver | 5 |
Denial of service in BIND named via naptr.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | sunos | 5.7 |
| sco | unixware | 2 |
| ibm | aix | 4.3 |
| sco | unixware | 7 |
| sco | openserver | 5 |
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0 |
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.2 |
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.2.1 |
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 3.2.5 |
| ibm | aix | 4.1.1 |
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1 |
| ibm | aix | 4.2 |
| ibm | aix | 3.2.5 |
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_cc_mail | 8.0 |
IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_opc_tracker_agent | 3.0x |
| ibm | tivoli_opc_tracker_agent | 2.0x |
| ibm | tivoli_opc_tracker_agent | 1.0x |
IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_opc_tracker_agent | 3.0x |
| ibm | tivoli_opc_tracker_agent | 2.0x |
| ibm | tivoli_opc_tracker_agent | 1.0x |
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 3.2.5 |
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| hp | hp-ux | 10.01 |
| hp | hp-ux | 10.20 |
| hp | hp-ux | 9.05 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netfinity_remote_control | * |
(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 4.1.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_data_repository | sp_2.0 |
Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | homepageprint | 1.0.7 |
netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | navio_nc_browser | 1.1.0.1 |
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | * |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.0 |
Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 1.3 |
| ibm | aix | 3.1 |
| ibm | aix | 3.2 |
| ibm | aix | 2.2.1 |
| ibm | aix | 1.2.1 |
IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | network_station_manager | 2.0r1 |
AIX techlibss allows local users to overwrite files via a symlink attack.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.2 |
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3 |
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.4 |
| ibm | aix | 4.1.5 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.1 |
| ibm | aix | 3.2.5 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.1.2 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.1.1 |
AIX cdmount allows local users to gain root privileges via shell metacharacters.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3 |
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-178,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0.2 |
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | 1.3.3 |
| apache | http_server | 1.3.9 |
| ibm | http_server | 1.3.6.2 |
| apache | http_server | 1.3.12 |
| apache | http_server | 1.3.6 |
| apache | http_server | 1.3.11 |
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 3.0.21 |
Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.data | * |
OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os2_ftp_server | 4.2 |
| ibm | os2_ftp_server | 4.3 |
| ibm | os2_ftp_server | 4.0 |
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 2.2 |
| redhat | linux | 5.1 |
| sgi | irix | 6.5.3f |
| trustix | secure_linux | 1.1 |
| turbolinux | turbolinux | 6.0.4 |
| mandrakesoft | mandrake_linux | 7.0 |
| suse | suse_linux | 6.3 |
| ibm | aix | 3.2.5 |
| suse | suse_linux | 7.0 |
| sun | sunos | 5.7 |
| debian | debian_linux | 2.3 |
| turbolinux | turbolinux | 6.0.2 |
| caldera | openlinux_ebuilder | 3.0 |
| caldera | openlinux_eserver | 2.3 |
| sgi | irix | 6.5.6 |
| trustix | secure_linux | 1.0 |
| turbolinux | turbolinux | 6.0.1 |
| ibm | aix | 3.2.4 |
| sgi | irix | 6.5 |
| sgi | irix | 6.5.3 |
| mandrakesoft | mandrake_linux | 7.1 |
| turbolinux | turbolinux | 6.0 |
| redhat | linux | 5.2 |
| ibm | aix | 4.2.1 |
| redhat | linux | 6.1 |
| conectiva | linux | 4.2 |
| sun | sunos | 5.5 |
| sgi | irix | 6.5.7 |
| debian | debian_linux | 2.0 |
| sgi | irix | 6.5.8 |
| conectiva | linux | 5.1 |
| sun | sunos | 5.8 |
| ibm | aix | 4.1.3 |
| ibm | aix | 4.1.2 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| sun | sunos | 5.1 |
| immunix | immunix | 6.2 |
| sgi | irix | 6.5.2m |
| sun | sunos | 5.4 |
| caldera | openlinux | * |
| sgi | irix | 6.4 |
| ibm | aix | 4.1.5 |
| suse | suse_linux | 6.2 |
| slackware | slackware_linux | 7.0 |
| redhat | linux | 6.0 |
| conectiva | linux | 4.0es |
| slackware | slackware_linux | 7.1 |
| ibm | aix | 4.1 |
| sgi | irix | 6.5.1 |
| suse | suse_linux | 6.4 |
| turbolinux | turbolinux | 6.0.3 |
| conectiva | linux | 4.1 |
| sgi | irix | 6.5.4 |
| conectiva | linux | 4.0 |
| sgi | irix | 6.5.3m |
| sgi | irix | 6.3 |
| ibm | aix | 4.1.4 |
| sun | sunos | 5.5.1 |
| ibm | aix | 4.1.1 |
| sun | sunos | 5.0 |
| redhat | linux | 5.0 |
| sun | sunos | 5.2 |
| redhat | linux | 6.2 |
| sun | sunos | 5.3 |
| suse | suse_linux | 6.1 |
| sun | solaris | 2.6 |
| debian | debian_linux | 2.1 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| conectiva | linux | 5.0 |
| ibm | aix | 4.0 |
| ibm | aix | 4.3 |
| sgi | irix | 6.2 |
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0.2 |
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.2 |
A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | as400_firewall | r440 |
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.data | 7.0 |
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-203,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | r5 |
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.2 |
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.2 |
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.2 |
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | aix | 4.2.1 |
| ibm | aix | 4.2 |
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 5.0.2 |
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | 1.3.6.3 |
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server_ssl_module_common | 1.0 |
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.8 |
Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.0 |
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 3.7.1 |
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 6.1 |
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 6.1 |
| ibm | db2_universal_database | 7.1 |
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.52 |
| ibm | http_server | 1.3.12.2 |
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_plugin | * |
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.commerce | 3.2 |
| ibm | websphere_commerce_suite | 3.2 |
| ibm | net.commerce | 3.1 |
| ibm | net.commerce | 3.1.2 |
| ibm | net.commerce | 3.1.1 |
| ibm | net.commerce_hosting_server | 3.2 |
| ibm | net.commerce_hosting_server | 3.1.2 |
| ibm | websphere_commerce_suite | 3.1.2 |
| ibm | net.commerce | 3.0 |
| ibm | net.commerce | 2.0 |
| ibm | websphere_commerce_suite | 4.1 |
| ibm | net.commerce_hosting_server | 3.1.1 |
| ibm | websphere_commerce_suite | 4.1.1 |
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.commerce | 3.1.2 |
| ibm | websphere_application_server | 5.1.0.3 |
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.commerce | 3.1 |
| ibm | net.commerce | 3.1.2 |
| ibm | net.commerce | 3.1.1 |
| ibm | net.commerce | 3.0 |
| ibm | net.commerce | 2.0 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | net.commerce_hosting_server | 3.1.1 |
| ibm | net.commerce_hosting_server | 3.1.2 |
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce_suite | 4.0.1 |
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | high_availability_cluster_multiprocessing | 1.0 |
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix_snmp | * |
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3 |
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | openview_network_node_manager | 5.01 |
| hp | openview_network_node_manager | 6.1 |
| ibm | tivoli_netview | 6.0 |
| ibm | tivoli_netview | 5.0 |
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 2.2 |
| netbsd | netbsd | 1.4.1 |
| netbsd | netbsd | 1.4.3 |
| ibm | aix | 4.3.3 |
| freebsd | freebsd | 2.2.4 |
| mit | kerberos_5 | 1.2.1 |
| freebsd | freebsd | 4.3 |
| openbsd | openbsd | 2.3 |
| sun | sunos | 5.7 |
| freebsd | freebsd | 2.2.2 |
| openbsd | openbsd | 2.5 |
| netkit | linux_netkit | 0.11 |
| freebsd | freebsd | 2.1.6.1 |
| freebsd | freebsd | 2.0.5 |
| mit | kerberos | 1.0 |
| openbsd | openbsd | 2.0 |
| netbsd | netbsd | 1.3 |
| freebsd | freebsd | 4.2 |
| netbsd | netbsd | 1.2.1 |
| sgi | irix | 6.5 |
| netbsd | netbsd | 1.1 |
| mit | kerberos_5 | 1.1.1 |
| ibm | aix | 5.1 |
| freebsd | freebsd | 2.2.1 |
| netbsd | netbsd | 1.5.1 |
| openbsd | openbsd | 2.1 |
| freebsd | freebsd | 4.0 |
| sun | sunos | 5.5 |
| openbsd | openbsd | 2.6 |
| netbsd | netbsd | 1.5 |
| freebsd | freebsd | 2.2.5 |
| netbsd | netbsd | 1.2 |
| sun | sunos | 5.8 |
| openbsd | openbsd | 2.8 |
| openbsd | openbsd | 2.2 |
| freebsd | freebsd | 2.2.3 |
| openbsd | openbsd | 2.7 |
| freebsd | freebsd | 2.1.6 |
| freebsd | freebsd | 4.1 |
| freebsd | freebsd | 4.1.1 |
| freebsd | freebsd | 3.1 |
| freebsd | freebsd | 2.0.1 |
| sun | sunos | 5.1 |
| freebsd | freebsd | 3.5.1 |
| sun | sunos | 5.4 |
| mit | kerberos_5 | 1.2.2 |
| netbsd | netbsd | 1.3.2 |
| mit | kerberos_5 | 1.2 |
| freebsd | freebsd | 3.2 |
| netkit | linux_netkit | 0.12 |
| freebsd | freebsd | 2.2.6 |
| netbsd | netbsd | 1.3.1 |
| netkit | linux_netkit | 0.10 |
| freebsd | freebsd | 2.2.8 |
| freebsd | freebsd | 2.1.0 |
| freebsd | freebsd | 3.5 |
| freebsd | freebsd | 2.2 |
| freebsd | freebsd | 2.1.7 |
| freebsd | freebsd | 3.0 |
| freebsd | freebsd | 3.4 |
| sun | sunos | 5.5.1 |
| freebsd | freebsd | 2.2.7 |
| sun | sunos | 5.0 |
| freebsd | freebsd | 2.0 |
| netbsd | netbsd | 1.3.3 |
| sun | sunos | 5.2 |
| sun | sunos | 5.3 |
| freebsd | freebsd | 3.3 |
| netbsd | netbsd | 1.4.2 |
| freebsd | freebsd | 2.1.7.1 |
| sun | solaris | 2.6 |
| netbsd | netbsd | 1.0 |
| openbsd | openbsd | 2.4 |
| ibm | aix | 4.3.1 |
| freebsd | freebsd | 2.1 |
| ibm | aix | 4.3.2 |
| netbsd | netbsd | 1.4 |
| mit | kerberos_5 | 1.1 |
| ibm | aix | 4.3 |
| freebsd | freebsd | 2.1.5 |
lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4 |
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3 |
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | solaris | 7.0 |
| hp | hp-ux | 10.10 |
| sgi | irix | 3.3.2 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| sgi | irix | 3.2 |
| sun | sunos | - |
| sco | openserver | 5.0.6 |
| sgi | irix | 3.3.3 |
| sco | openserver | 5.0.5 |
| sun | solaris | 2.5 |
| sun | sunos | 5.7 |
| sco | openserver | 5.0.4 |
| hp | hp-ux | 11.0.4 |
| hp | hp-ux | 10.00 |
| sgi | irix | 3.3.1 |
| sco | openserver | 5.0.3 |
| sun | sunos | 5.5.1 |
| sun | sunos | 5.0 |
| sco | openserver | 5.0 |
| ibm | aix | 5.1 |
| sun | sunos | 5.2 |
| hp | hp-ux | 10.01 |
| sun | sunos | 5.3 |
| sco | openserver | 5.0.1 |
| hp | hp-ux | 10.24 |
| sco | openserver | 5.0.6a |
| sun | sunos | 5.5 |
| hp | hp-ux | 11.00 |
| sun | solaris | 2.6 |
| sun | solaris | 8.0 |
| sun | solaris | 2.5.1 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| sun | sunos | 5.8 |
| sun | solaris | 2.4 |
| hp | hp-ux | 10.20 |
| ibm | aix | 4.3 |
| sco | openserver | 5.0.2 |
| sgi | irix | 3.3 |
| sun | sunos | 5.1 |
| sun | sunos | 5.4 |
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.5 |
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | 4758 | * |
Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_web_datablade | 3.7 |
| ibm | informix_web_datablade | 3.6 |
| ibm | informix_web_datablade | 4.12 |
| ibm | informix_web_datablade | 4.10 |
| ibm | informix_web_datablade | 4.11 |
| ibm | informix_web_datablade | 3.3 |
| ibm | informix_web_datablade | 3.4 |
| ibm | informix_web_datablade | 3.5 |
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce_suite | 3.1.2 |
| ibm | websphere_commerce_suite | 3.2 |
| ibm | websphere_application_server | * |
Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_secureway_policy_director | 3.7 |
| ibm | tivoli_secureway_policy_director | 3.7.1 |
| ibm | tivoli_secureway_policy_director | 3.0.1 |
| ibm | tivoli_secureway_policy_director | 3.6 |
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | hacmp | 4.4 |
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.0 |
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3 |
Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.0 |
Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.0 |
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.0 |
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 3.0.2.1 |
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_secureway_policy_director | 3.8 |
Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | alphaworks_tftp_server | 1.21 |
Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | secureway_directory | 3.2.1 |
IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | secureway_directory | 3.2.1 |
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_r5 | * |
Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_r5 | * |
Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_r5 | * |
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.2.0 |
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.2.0 |
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1l |
Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | visualage_for_java | 3.5 |
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 5.0 |
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 430 |
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3 |
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_domino_server | * |
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 4.6 |
| ibm | lotus_domino_server | 5 |
| ibm | lotus_domino_server | 4.5 |
Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 5.0.4 |
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 5.0.9a |
| microsoft | windows_98_plus_pack | * |
| winzip | winzip | 7.0 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | r5 |
| microsoft | windows_xp | * |
| ibm | lotus_notes | r6 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0 |
| allume_systems_division | stuffit_expander | 6.5.2 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 5.0.4 |
| verity | keyview_viewing_sdk | gold |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.10 |
| microsoft | windows_me | * |
| ibm | lotus_notes | 5.0.2 |
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 4.2 |
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_web_datablade | 4.12 |
| ibm | informix_web_datablade | 4.10 |
| ibm | informix_web_datablade | 4.11 |
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_web_datablade | 4.12 |
| ibm | informix_web_datablade | 4.10 |
| ibm | informix_web_datablade | 4.11 |
| ibm | informix_web_datablade | 4.13 |
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| sgi | irix | 6.0 |
| hp | hp-ux | 10.10 |
| sgi | irix | 6.5.15 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| caldera | unixware | 7.1_.0 |
| sgi | irix | 6.5.2 |
| xi_graphics | dextop | 2.1 |
| sgi | irix | 6.5.1 |
| caldera | unixware | 7 |
| sun | sunos | 5.7 |
| caldera | openunix | 8.0 |
| caldera | unixware | 7.1.1 |
| sgi | irix | 6.5.4 |
| sgi | irix | 6.3 |
| sgi | irix | 6.5.12 |
| sgi | irix | 6.5.6 |
| compaq | tru64 | 4.0g |
| compaq | tru64 | 5.1a |
| sun | sunos | 5.5.1 |
| sgi | irix | 5.2 |
| sgi | irix | 6.5 |
| sgi | irix | 6.5.3 |
| sgi | irix | 6.5.10 |
| sgi | irix | 6.0.1 |
| sgi | irix | 6.5.5 |
| sgi | irix | 6.5.14 |
| ibm | aix | 5.1 |
| sgi | irix | 6.5.16 |
| hp | hp-ux | 10.24 |
| hp | hp-ux | 11.00 |
| sgi | irix | 6.5.7 |
| compaq | tru64 | 5.1 |
| compaq | tru64 | 5.0a |
| sun | solaris | 2.6 |
| compaq | tru64 | 4.0f |
| sgi | irix | 6.5.8 |
| sun | sunos | 5.8 |
| sgi | irix | 6.5.11 |
| sgi | irix | 6.5.13 |
| hp | hp-ux | 10.20 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| sgi | irix | 5.3 |
| sgi | irix | 6.5.9 |
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.4 |
| caldera | unixware | 7.1.0 |
| sgi | irix | 6.0 |
| hp | hp-ux | 10.10 |
| sgi | irix | 6.5.15 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| sgi | irix | 6.5.2 |
| xi_graphics | dextop | 2.1 |
| sgi | irix | 6.5.1 |
| sun | sunos | 5.7 |
| caldera | openunix | 8.0 |
| caldera | unixware | 7.1.1 |
| sgi | irix | 6.5.4 |
| sgi | irix | 6.3 |
| sgi | irix | 6.5.12 |
| sgi | irix | 6.5.6 |
| compaq | tru64 | 4.0g |
| compaq | tru64 | 5.1a |
| sun | sunos | 5.5.1 |
| sgi | irix | 5.2 |
| sgi | irix | 6.5 |
| sgi | irix | 6.5.3 |
| sgi | irix | 6.5.10 |
| sgi | irix | 6.0.1 |
| sgi | irix | 6.5.5 |
| sgi | irix | 6.5.14 |
| ibm | aix | 5.1 |
| caldera | unixware | 7.0 |
| sgi | irix | 6.5.16 |
| hp | hp-ux | 10.24 |
| hp | hp-ux | 11.00 |
| sgi | irix | 6.5.7 |
| compaq | tru64 | 5.1 |
| compaq | tru64 | 5.0a |
| sun | solaris | 2.6 |
| compaq | tru64 | 4.0f |
| sgi | irix | 6.5.8 |
| sun | sunos | 5.8 |
| sgi | irix | 6.5.11 |
| sgi | irix | 6.5.13 |
| hp | hp-ux | 10.20 |
| sgi | irix | 6.2 |
| sgi | irix | 6.1 |
| sgi | irix | 5.3 |
| sgi | irix | 6.5.9 |
| sun | solaris | 9.0 |
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| caldera | unixware | 7.1.0 |
| hp | hp-ux | 10.10 |
| ibm | aix | 5.1 |
| caldera | unixware | 7.0 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| hp | hp-ux | 10.24 |
| xi_graphics | dextop | 2.1 |
| hp | hp-ux | 11.00 |
| compaq | tru64 | 5.1 |
| compaq | tru64 | 5.0a |
| sun | solaris | 2.6 |
| compaq | tru64 | 4.0f |
| sun | sunos | 5.7 |
| caldera | openunix | 8.0 |
| sun | sunos | 5.8 |
| caldera | unixware | 7.1.1 |
| hp | hp-ux | 10.20 |
| compaq | tru64 | 4.0g |
| compaq | tru64 | 5.1a |
| sun | sunos | 5.5.1 |
| sun | solaris | 9.0 |
Buffer overflow in pioout on AIX 4.3.3.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
Buffer overflow in uucp in AIX 4.3.3.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
Buffer overflow in lsmcode in AIX 4.3.3.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix | 7.25_.uc3_se |
| ibm | informix | 7.25_.uc2_se |
| ibm | informix | 7.25_.uc1_se |
Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 3.6 |
| ibm | tivoli_management_framework | 3.7.1 |
| ibm | tivoli_management_framework | 3.6.1 |
| ibm | tivoli_management_framework | 3.7 |
Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 3.6 |
| ibm | tivoli_management_framework | 3.7.1 |
| ibm | tivoli_management_framework | 3.6.1 |
| ibm | tivoli_management_framework | 3.7 |
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 4.0.3 |
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_caching_proxy_server | 4.0 |
| ibm | websphere_caching_proxy_server | 3.6 |
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_caching_proxy_server | 4.0 |
| ibm | websphere_caching_proxy_server | 3.6 |
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_caching_proxy_server | 4.0 |
| ibm | websphere_caching_proxy_server | 3.6 |
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5 |
| ibm | aix | 4.3.3 |
IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | secureway_firewall | 4.2 |
| ibm | secureway_firewall | 4.2.1 |
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | u2_universe | * |
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.0 |
dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.2 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 6.0 |
| ibm | db2_universal_database | 7.0 |
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix_parallel_systems_support_programs | 3.4 |
| ibm | aix_parallel_systems_support_programs | 3.2 |
| ibm | aix_parallel_systems_support_programs | 3.1.1 |
Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_domino | 5.0.6 |
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.5 |
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 3.2.5 |
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | v4r2 |
| ibm | os_400 | v4r3 |
| ibm | os_400 | v4r5 |
| ibm | os_400 | v5r1 |
| ibm | os_400 | v4r4 |
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | 1.0 |
Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.8 |
Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 5.0.2 |
| ibm | lotus_domino_server | 4.6.1 |
| ibm | lotus_domino_server | 5.0.8 |
| ibm | lotus_domino_server | 5.0.1 |
| ibm | lotus_domino_server | 5.0.4 |
| ibm | lotus_domino_server | 5.0.5 |
| ibm | lotus_domino_server | 5.0.9 |
| ibm | lotus_domino_server | 4.6.3 |
| ibm | lotus_domino_server | 5.0 |
| ibm | lotus_domino_server | 4.6.4 |
| ibm | lotus_domino_server | 5.0.7a |
| ibm | lotus_domino_server | 5.0.6 |
| ibm | lotus_domino_server | 5.0.3 |
| ibm | lotus_domino_server | 5.0.7 |
The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infoprint_21 | 1.047012 |
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| openbsd | openbsd | 3.2 |
| openafs | openafs | 1.0.3 |
| mit | kerberos_5 | 1.2.1 |
| freebsd | freebsd | 4.3 |
| openafs | openafs | 1.2.4 |
| openafs | openafs | 1.2.3 |
| openbsd | openbsd | 2.5 |
| sgi | irix | 6.5.16m |
| sgi | irix | 6.5.15f |
| cray | unicos | 6.1 |
| openbsd | openbsd | 2.0 |
| sgi | irix | 6.5.13f |
| freebsd | freebsd | 4.2 |
| sgi | irix | 6.5.11f |
| sgi | irix | 6.5 |
| openafs | openafs | 1.2.2a |
| ibm | aix | 5.1 |
| openbsd | openbsd | 2.1 |
| freebsd | freebsd | 4.0 |
| freebsd | freebsd | 4.5 |
| sgi | irix | 6.5.7 |
| sgi | irix | 6.5.7f |
| sgi | irix | 6.5.8 |
| openafs | openafs | 1.1.1a |
| gnu | glibc | 2.1 |
| hp | hp-ux_series_800 | 10.20 |
| sun | sunos | 5.8 |
| openafs | openafs | 1.0.4 |
| hp | hp-ux | 10.20 |
| openbsd | openbsd | 2.7 |
| cray | unicos | 9.0.2.5 |
| freebsd | freebsd | 4.1 |
| freebsd | freebsd | 4.1.1 |
| sgi | irix | 6.5.4m |
| cray | unicos | 6.0e |
| sun | solaris | 7.0 |
| mit | kerberos_5 | 1.2.2 |
| sgi | irix | 6.5.5m |
| sgi | irix | 6.5.15 |
| gnu | glibc | 2.2.1 |
| sgi | irix | 6.5.19 |
| openafs | openafs | 1.2 |
| sgi | irix | 6.5.2 |
| sgi | irix | 6.5.1 |
| sgi | irix | 6.5.12m |
| openafs | openafs | 1.2.2 |
| mit | kerberos_5 | 1.2.3 |
| cray | unicos | 7.0 |
| gnu | glibc | 2.2.4 |
| mit | kerberos_5 | 1.2.5 |
| cray | unicos | 9.2 |
| sgi | irix | 6.5.17 |
| gnu | glibc | 2.3.1 |
| sun | sunos | 5.5.1 |
| sgi | irix | 6.5.15m |
| mit | kerberos_5 | 1.2.7 |
| sgi | irix | 6.5.16 |
| openafs | openafs | 1.0.4a |
| hp | hp-ux | 10.24 |
| sgi | irix | 6.5.17f |
| sun | solaris | 2.6 |
| openafs | openafs | 1.2.6 |
| hp | hp-ux_series_700 | 10.20 |
| openafs | openafs | 1.0.2 |
| freebsd | freebsd | 4.6.2 |
| gnu | glibc | 2.3 |
| openafs | openafs | 1.2.2b |
| cray | unicos | 6.0 |
| mit | kerberos_5 | 1.2.6 |
| sgi | irix | 6.5.3f |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| sgi | irix | 6.5.20 |
| freebsd | freebsd | 4.4 |
| openbsd | openbsd | 3.0 |
| cray | unicos | 8.3 |
| gnu | glibc | 2.3.2 |
| gnu | glibc | 2.1.2 |
| sgi | irix | 6.5.9m |
| sgi | irix | 6.5.14m |
| gnu | glibc | 2.2 |
| openbsd | openbsd | 2.3 |
| sun | sunos | 5.7 |
| sgi | irix | 6.5.16f |
| gnu | glibc | 2.2.5 |
| cray | unicos | 9.2.4 |
| openafs | openafs | 1.2.1 |
| sgi | irix | 6.5.6 |
| sgi | irix | 6.5.3 |
| openbsd | openbsd | 2.9 |
| openafs | openafs | 1.2.5 |
| gnu | glibc | 2.1.3 |
| ibm | aix | 5.2 |
| hp | hp-ux | 11.00 |
| openbsd | openbsd | 2.6 |
| sgi | irix | 6.5.6f |
| sun | solaris | 8.0 |
| sgi | irix | 6.5.9f |
| sun | solaris | 2.5.1 |
| sgi | irix | 6.5.2f |
| sgi | irix | 6.5.13 |
| openbsd | openbsd | 2.8 |
| mit | kerberos_5 | 1.2.4 |
| openbsd | openbsd | 2.2 |
| openafs | openafs | 1.0.1 |
| openafs | openafs | 1.1 |
| sgi | irix | 6.5.9 |
| gnu | glibc | 2.2.3 |
| sgi | irix | 6.5.2m |
| hp | hp-ux | 11.04 |
| openafs | openafs | 1.3 |
| sun | solaris | 9.0 |
| sgi | irix | 6.5.18 |
| sgi | irix | 6.5.4f |
| hp | hp-ux | 11.22 |
| openafs | openafs | 1.3.1 |
| mit | kerberos_5 | 1.2 |
| hp | hp-ux | 11.20 |
| gnu | glibc | 2.2.2 |
| sgi | irix | 6.5.18f |
| sun | sunos | - |
| sgi | irix | 6.5.10m |
| freebsd | freebsd | 4.7 |
| cray | unicos | 8.0 |
| openafs | openafs | 1.3.2 |
| sgi | irix | 6.5.4 |
| sgi | irix | 6.5.3m |
| freebsd | freebsd | 5.0 |
| sgi | irix | 6.5.8f |
| sgi | irix | 6.5.12 |
| openafs | openafs | 1.1.1 |
| openafs | openafs | 1.0 |
| sgi | irix | 6.5.7m |
| sgi | irix | 6.5.10 |
| sgi | irix | 6.5.5 |
| sgi | irix | 6.5.11m |
| sgi | irix | 6.5.6m |
| sgi | irix | 6.5.14 |
| openbsd | openbsd | 3.1 |
| sgi | irix | 6.5.14f |
| sgi | irix | 6.5.12f |
| sgi | irix | 6.5.13m |
| openbsd | openbsd | 2.4 |
| sgi | irix | 6.5.11 |
| sgi | irix | 6.5.8m |
| sgi | irix | 6.5.10f |
| sgi | irix | 6.5.17m |
| cray | unicos | 9.0 |
| sgi | irix | 6.5.5f |
| freebsd | freebsd | 4.6 |
| sgi | irix | 6.5.18m |
| gnu | glibc | 2.1.1 |
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | irix | 6.5.3f |
| sgi | irix | 6.0 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| sgi | irix | 6.5.9m |
| hp | hp-ux | 10.34 |
| sgi | irix | 6.5.14m |
| sun | sunos | 5.7 |
| sgi | irix | 6.5.16f |
| sgi | irix | 5.0.1 |
| sgi | irix | 6.5.16m |
| sgi | irix | 6.5.15f |
| sgi | irix | 6.5.6 |
| sgi | irix | 6.5.13f |
| sgi | irix | 6.5.11f |
| sgi | irix | 5.2 |
| sgi | irix | 6.5 |
| sgi | irix | 6.5.3 |
| ibm | aix | 5.1 |
| ibm | aix | 5.2 |
| hp | hp-ux | 11.00 |
| sgi | irix | 6.5.7 |
| sgi | irix | 6.5.7f |
| sgi | irix | 6.5.6f |
| sun | solaris | 8.0 |
| sgi | irix | 6.5.9f |
| sun | solaris | 2.5.1 |
| sgi | irix | 6.5.8 |
| sgi | irix | 6.5.2f |
| sun | sunos | 5.8 |
| sgi | irix | 6.5.13 |
| hp | hp-ux | 10.20 |
| sgi | irix | 5.3 |
| sgi | irix | 6.5.4m |
| sgi | irix | 6.5.9 |
| sgi | irix | 6.5.2m |
| hp | hp-ux | 11.04 |
| sun | solaris | 9.0 |
| sgi | irix | 6.5.18 |
| sun | solaris | 7.0 |
| sgi | irix | 6.4 |
| sgi | irix | 6.5.4f |
| sgi | irix | 6.5.5m |
| sgi | irix | 6.5.15 |
| hp | hp-ux | 11.22 |
| hp | hp-ux | 11.20 |
| sgi | irix | 6.5.18f |
| sgi | irix | 6.5.2 |
| sgi | irix | 6.5.1 |
| sun | sunos | - |
| sgi | irix | 6.5.12m |
| sgi | irix | 6.5.10m |
| sgi | irix | 5.1.1 |
| hp | hp-ux | 10.30 |
| hp | hp-ux | 10.26 |
| sgi | irix | 6.5.4 |
| sgi | irix | 6.5.3m |
| sgi | irix | 6.5.8f |
| sgi | irix | 6.3 |
| sgi | irix | 6.5.12 |
| sgi | irix | 6.5.17 |
| sgi | irix | 5.0 |
| sun | sunos | 5.5.1 |
| sgi | irix | 6.5.7m |
| sgi | irix | 6.5.15m |
| sgi | irix | 6.5.10 |
| sgi | irix | 6.0.1 |
| sgi | irix | 6.5.5 |
| sgi | irix | 6.5.11m |
| sgi | irix | 6.5.6m |
| sgi | irix | 6.5.14 |
| sgi | irix | 6.5.16 |
| hp | hp-ux | 10.24 |
| sgi | irix | 6.5.17f |
| sgi | irix | 6.5.14f |
| sgi | irix | 6.5.12f |
| sgi | irix | 6.5.13m |
| sun | solaris | 2.6 |
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| sgi | irix | 6.5.11 |
| sgi | irix | 6.5.8m |
| ibm | aix | 4.3 |
| sgi | irix | 6.5.10f |
| sgi | irix | 6.2 |
| sgi | irix | 6.5.17m |
| sgi | irix | 6.1 |
| sgi | irix | 5.1 |
| sgi | irix | 6.5.5f |
| sgi | irix | 6.5.18m |
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 5.2 |
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_notes_client | r5 |
| ibm | lotus_notes_client | 5.0.1 |
| ibm | lotus_domino | 5.0.10 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.8a |
| ibm | lotus_notes_client | 5.0.9a |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_notes_client | 5.0.2 |
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_notes_client | 5.0.10 |
| ibm | lotus_domino | 4.6.4 |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 5.0.11 |
| ibm | lotus_notes_client | 5.0.11 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 4.6.3 |
| ibm | lotus_notes_client | 5.0.3 |
| ibm | lotus_domino | 4.6.1 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_notes_client | 5.0.5 |
| ibm | lotus_notes_client | 5.0 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_notes_client | 5.0.4 |
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_notes_client | r5 |
| ibm | lotus_notes_client | 5.0.1 |
| ibm | lotus_domino | 5.0.10 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.8a |
| ibm | lotus_notes_client | 5.0.9a |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_notes_client | 5.0.2 |
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_notes_client | 5.0.10 |
| ibm | lotus_domino | 4.6.4 |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 5.0.11 |
| ibm | lotus_notes_client | 5.0.11 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 4.6.3 |
| ibm | lotus_notes_client | 5.0.3 |
| ibm | lotus_domino | 4.6.1 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_notes_client | 5.0.5 |
| ibm | lotus_notes_client | 5.0 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_notes_client | 5.0.4 |
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2 |
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_server | 6.0 |
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_client | 6.0 |
| ibm | lotus_domino_web_server | 6.0 |
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_server | 6.0 |
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_server | 6.0 |
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.1 |
| ibm | aix | 4.3.2 |
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 4.3 |
| ibm | aix | 5.2 |
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | u2_universe | * |
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | u2_universe | * |
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | u2_universe | * |
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| openbsd | openbsd | 3.2 |
| sendmail | sendmail | 2.6.1 |
| netbsd | netbsd | 1.4.3 |
| sendmail | sendmail | 8.10 |
| netbsd | netbsd | 1.5.3 |
| sendmail | sendmail | 8.11.6 |
| gentoo | linux | 1.2 |
| sendmail | sendmail | 8.11.3 |
| sendmail | sendmail | 8.9.2 |
| sendmail | sendmail_switch | 2.2.1 |
| apple | mac_os_x | 10.2.2 |
| sendmail | sendmail_switch | 2.2.4 |
| ibm | aix | 5.1 |
| sendmail | sendmail | 8.12.1 |
| sendmail | sendmail | 8.11.5 |
| gentoo | linux | 0.7 |
| sendmail | sendmail_pro | 8.9.2 |
| apple | mac_os_x | 10.2.3 |
| sendmail | advanced_message_server | 1.2 |
| apple | mac_os_x_server | 10.2 |
| sendmail | sendmail_switch | 3.0 |
| openbsd | openbsd | 3.3 |
| sendmail | sendmail | 8.12.4 |
| sendmail | sendmail | 3.0 |
| sendmail | sendmail_switch | 2.2.3 |
| sendmail | sendmail_switch | 3.0.2 |
| sendmail | sendmail | 8.12.0 |
| sendmail | sendmail | 8.9.1 |
| gentoo | linux | 0.5 |
| apple | mac_os_x_server | 10.2.2 |
| netbsd | netbsd | 1.5.2 |
| sendmail | sendmail_switch | 2.1.4 |
| sendmail | advanced_message_server | 1.3 |
| sendmail | sendmail | 8.12.8 |
| sendmail | sendmail_switch | 2.1 |
| sendmail | sendmail | 8.10.2 |
| sendmail | sendmail | 8.12 |
| sendmail | sendmail | 8.12.6 |
| netbsd | netbsd | 1.6 |
| sendmail | sendmail_switch | 3.0.3 |
| apple | mac_os_x_server | 10.2.3 |
| apple | mac_os_x_server | 10.2.4 |
| sendmail | sendmail_switch | 2.2.2 |
| gentoo | linux | 1.4 |
| sendmail | sendmail | 8.8.8 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| gentoo | linux | 1.1a |
| turbolinux | turbolinux_workstation | 8.0 |
| sendmail | sendmail | 3.0.1 |
| sendmail | sendmail | 2.6.2 |
| hp | hp-ux | 11.0.4 |
| sendmail | sendmail | 8.12.2 |
| sendmail | sendmail_switch | 2.1.1 |
| apple | mac_os_x_server | 10.2.6 |
| sendmail | sendmail | 3.0.2 |
| netbsd | netbsd | 1.6.1 |
| turbolinux | turbolinux_server | 6.5 |
| turbolinux | turbolinux_server | 8.0 |
| apple | mac_os_x | 10.2.1 |
| sendmail | sendmail | 8.11.1 |
| sendmail | sendmail | 8.11.2 |
| sendmail | sendmail_switch | 2.2.5 |
| turbolinux | turbolinux_workstation | 6.0 |
| netbsd | netbsd | 1.5.1 |
| ibm | aix | 5.2 |
| turbolinux | turbolinux_workstation | 7.0 |
| sendmail | sendmail | 8.12.9 |
| hp | hp-ux | 11.00 |
| sendmail | sendmail_switch | 2.1.3 |
| netbsd | netbsd | 1.5 |
| sendmail | sendmail | 8.12.3 |
| sendmail | sendmail | 8.12.7 |
| sendmail | sendmail | 2.6 |
| sendmail | sendmail_pro | 8.9.3 |
| sendmail | sendmail | 8.12.5 |
| apple | mac_os_x_server | 10.2.5 |
| turbolinux | turbolinux_advanced_server | 6.0 |
| sendmail | sendmail_switch | 2.2 |
| apple | mac_os_x | 10.2.5 |
| sendmail | sendmail_switch | 3.0.1 |
| sendmail | sendmail | 8.10.1 |
| hp | hp-ux | 11.22 |
| sendmail | sendmail | 8.9.0 |
| sendmail | sendmail | 8.9.3 |
| sendmail | sendmail_switch | 2.1.5 |
| turbolinux | turbolinux_server | 6.1 |
| apple | mac_os_x | 10.2.6 |
| turbolinux | turbolinux_server | 7.0 |
| apple | mac_os_x_server | 10.2.1 |
| sendmail | sendmail | 8.11.0 |
| sendmail | sendmail_switch | 2.1.2 |
| sendmail | sendmail | 8.11.4 |
| apple | mac_os_x | 10.2.4 |
| sendmail | sendmail | 3.0.3 |
| apple | mac_os_x | 10.2 |
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sendmail | sendmail | 2.6.1 |
| netbsd | netbsd | 1.4.3 |
| sendmail | sendmail | 8.10 |
| compaq | tru64 | 4.0f_pk8_bl22 |
| freebsd | freebsd | 4.3 |
| netbsd | netbsd | 1.5.3 |
| sendmail | sendmail | 8.11.6 |
| gentoo | linux | 1.2 |
| sendmail | sendmail | 8.11.3 |
| sendmail | sendmail | 8.9.2 |
| compaq | tru64 | 5.1a_pk2_bl2 |
| sendmail | sendmail_switch | 2.2.1 |
| apple | mac_os_x | 10.2.2 |
| sendmail | sendmail_switch | 2.2.4 |
| compaq | tru64 | 5.1_pk3_bl17 |
| ibm | aix | 5.1 |
| compaq | tru64 | 4.0g_pk3_bl17 |
| freebsd | freebsd | 4.0 |
| freebsd | freebsd | 4.5 |
| sendmail | sendmail | 8.12.1 |
| sendmail | sendmail | 8.11.5 |
| gentoo | linux | 0.7 |
| freebsd | freebsd | 4.8 |
| sun | sunos | 5.8 |
| sendmail | sendmail_pro | 8.9.2 |
| compaq | tru64 | 5.1_pk4_bl18 |
| apple | mac_os_x | 10.2.3 |
| sendmail | advanced_message_server | 1.2 |
| apple | mac_os_x_server | 10.2 |
| sendmail | sendmail_switch | 3.0 |
| sun | solaris | 7.0 |
| sendmail | sendmail | 8.12.4 |
| compaq | tru64 | 5.1_pk5_bl19 |
| sendmail | sendmail | 3.0 |
| sendmail | sendmail_switch | 2.2.3 |
| sendmail | sendmail_switch | 3.0.2 |
| sgi | irix | 6.5.15 |
| sendmail | sendmail | 8.12.0 |
| sendmail | sendmail | 8.9.1 |
| gentoo | linux | 0.5 |
| apple | mac_os_x_server | 10.2.2 |
| netbsd | netbsd | 1.5.2 |
| sendmail | sendmail_switch | 2.1.4 |
| sendmail | advanced_message_server | 1.3 |
| sendmail | sendmail | 8.12.8 |
| sendmail | sendmail_switch | 2.1 |
| sendmail | sendmail | 8.10.2 |
| compaq | tru64 | 4.0g |
| compaq | tru64 | 5.1a |
| sendmail | sendmail | 8.12 |
| sgi | irix | 6.5.16 |
| sgi | irix | 6.5.20m |
| sgi | irix | 6.5.17f |
| sun | solaris | 2.6 |
| compaq | tru64 | 4.0f |
| sendmail | sendmail | 8.12.6 |
| netbsd | netbsd | 1.6 |
| sendmail | sendmail_switch | 3.0.3 |
| sgi | irix | 6.5.21f |
| apple | mac_os_x_server | 10.2.3 |
| compaq | tru64 | 5.1b_pk1_bl1 |
| apple | mac_os_x_server | 10.2.4 |
| sendmail | sendmail_switch | 2.2.2 |
| gentoo | linux | 1.4 |
| sendmail | sendmail | 8.8.8 |
| ibm | aix | 4.3.3 |
| hp | hp-ux | 11.11 |
| freebsd | freebsd | 4.4 |
| gentoo | linux | 1.1a |
| turbolinux | turbolinux_workstation | 8.0 |
| sgi | irix | 6.5.19f |
| sendmail | sendmail | 3.0.1 |
| compaq | tru64 | 4.0g_pk4_bl22 |
| sendmail | sendmail | 2.6.2 |
| sun | sunos | 5.7 |
| hp | hp-ux | 11.0.4 |
| sendmail | sendmail | 8.12.2 |
| sendmail | sendmail_switch | 2.1.1 |
| apple | mac_os_x_server | 10.2.6 |
| sendmail | sendmail | 3.0.2 |
| netbsd | netbsd | 1.6.1 |
| turbolinux | turbolinux_server | 6.5 |
| turbolinux | turbolinux_server | 8.0 |
| apple | mac_os_x | 10.2.1 |
| sendmail | sendmail | 8.11.1 |
| sendmail | sendmail | 8.11.2 |
| sgi | irix | 6.5.21m |
| sendmail | sendmail_switch | 2.2.5 |
| turbolinux | turbolinux_workstation | 6.0 |
| netbsd | netbsd | 1.5.1 |
| ibm | aix | 5.2 |
| turbolinux | turbolinux_workstation | 7.0 |
| sendmail | sendmail | 8.12.9 |
| hp | hp-ux | 11.00 |
| sgi | irix | 6.5.19m |
| sendmail | sendmail_switch | 2.1.3 |
| netbsd | netbsd | 1.5 |
| sendmail | sendmail | 8.12.3 |
| sun | solaris | 8.0 |
| sendmail | sendmail | 8.12.7 |
| sendmail | sendmail | 2.6 |
| compaq | tru64 | 4.0f_pk7_bl18 |
| sendmail | sendmail_pro | 8.9.3 |
| sendmail | sendmail | 8.12.5 |
| compaq | tru64 | 5.1b |
| apple | mac_os_x_server | 10.2.5 |
| compaq | tru64 | 5.1a_pk1_bl1 |
| turbolinux | turbolinux_advanced_server | 6.0 |
| sendmail | sendmail_switch | 2.2 |
| apple | mac_os_x | 10.2.5 |
| sendmail | sendmail_switch | 3.0.1 |
| sun | solaris | 9.0 |
| compaq | tru64 | 4.0f_pk6_bl17 |
| sendmail | sendmail | 8.10.1 |
| sgi | irix | 6.5.20f |
| hp | hp-ux | 11.22 |
| sendmail | sendmail | 8.9.0 |
| sendmail | sendmail | 8.9.3 |
| sendmail | sendmail_switch | 2.1.5 |
| sgi | irix | 6.5.18f |
| turbolinux | turbolinux_server | 6.1 |
| sun | sunos | - |
| compaq | tru64 | 5.1b_pk2_bl22 |
| freebsd | freebsd | 5.1 |
| freebsd | freebsd | 4.7 |
| apple | mac_os_x | 10.2.6 |
| freebsd | freebsd | 3.0 |
| freebsd | freebsd | 5.0 |
| turbolinux | turbolinux_server | 7.0 |
| apple | mac_os_x_server | 10.2.1 |
| compaq | tru64 | 5.1a_pk4_bl21 |
| compaq | tru64 | 5.1_pk6_bl20 |
| compaq | tru64 | 5.1 |
| freebsd | freebsd | 4.9 |
| sendmail | sendmail | 8.11.0 |
| compaq | tru64 | 5.1a_pk5_bl23 |
| sgi | irix | 6.5.17m |
| sendmail | sendmail_switch | 2.1.2 |
| sendmail | sendmail | 8.11.4 |
| compaq | tru64 | 5.1a_pk3_bl3 |
| apple | mac_os_x | 10.2.4 |
| freebsd | freebsd | 4.6 |
| sendmail | sendmail | 3.0.3 |
| sgi | irix | 6.5.18m |
| apple | mac_os_x | 10.2 |
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.2 |
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3 |
| ibm | aix | 5.2 |
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 5.2 |
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 7.1 |
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.1 |
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 7.1 |
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | hp-ux | 11.11 |
| isc | bind | 8.2.6 |
| freebsd | freebsd | 4.4 |
| compaq | tru64 | 4.0f_pk8_bl22 |
| compaq | tru64 | 4.0g_pk4_bl22 |
| nixu | namesurfer | standard_3.0.1 |
| sun | sunos | 5.7 |
| compaq | tru64 | 5.1a_pk2_bl2 |
| isc | bind | 8.2.3 |
| isc | bind | 8.2.4 |
| netbsd | netbsd | 1.6.1 |
| ibm | aix | 5.1l |
| compaq | tru64 | 5.1_pk3_bl17 |
| isc | bind | 8.3.0 |
| compaq | tru64 | 4.0g_pk3_bl17 |
| freebsd | freebsd | 4.5 |
| hp | hp-ux | 11.00 |
| sun | solaris | 8.0 |
| isc | bind | 8.3.3 |
| freebsd | freebsd | 4.8 |
| nixu | namesurfer | suite_3.0.1 |
| sun | sunos | 5.8 |
| compaq | tru64 | 4.0f_pk7_bl18 |
| compaq | tru64 | 5.1_pk4_bl18 |
| compaq | tru64 | 5.1b |
| compaq | tru64 | 5.1a_pk1_bl1 |
| sco | unixware | 7.1.1 |
| sun | solaris | 9.0 |
| isc | bind | 8.3.1 |
| netbsd | netbsd | current |
| sun | solaris | 7.0 |
| compaq | tru64 | 4.0f_pk6_bl17 |
| compaq | tru64 | 5.1_pk5_bl19 |
| isc | bind | 8.2.7 |
| isc | bind | 8.3.4 |
| compaq | tru64 | 5.1b_pk2_bl22 |
| freebsd | freebsd | 4.7 |
| isc | bind | 8.4.1 |
| isc | bind | 8.3.2 |
| freebsd | freebsd | 5.0 |
| compaq | tru64 | 4.0g |
| compaq | tru64 | 5.1a |
| isc | bind | 8.4 |
| isc | bind | 8.3.6 |
| compaq | tru64 | 5.1a_pk4_bl21 |
| compaq | tru64 | 5.1_pk6_bl20 |
| compaq | tru64 | 5.1 |
| isc | bind | 8.2.5 |
| freebsd | freebsd | 4.9 |
| compaq | tru64 | 4.0f |
| netbsd | netbsd | 1.6 |
| freebsd | freebsd | 4.6.2 |
| isc | bind | 8.3.5 |
| compaq | tru64 | 5.1b_pk1_bl1 |
| compaq | tru64 | 5.1a_pk5_bl23 |
| compaq | tru64 | 5.1a_pk3_bl3 |
| freebsd | freebsd | 4.6 |
Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 5.2 |
Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 5.2 |
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.0 |
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.0 |
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2 | 9.0 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.2 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 6.0 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_firewall_toolbox | 1.2 |
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 4.0.4 |
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| iss | blackice_server_protection | 3.5.cdf |
| ibm | internet_security_systems_blackice_defender | 2.9cap |
The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 5.1.10 |
| ibm | tivoli_storage_manager | 5.2.0 |
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.0.2 |
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-203,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloudscape | 5.1 |
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.0.46 |
| apache | http_server | 2.0.36 |
| apache | http_server | 1.3.6 |
| apache | http_server | 1.3.11 |
| apache | http_server | 2.0.32 |
| apache | http_server | 1.0.3 |
| apache | http_server | 2.0.47 |
| ibm | http_server | 1.3.19 |
| apache | http_server | 1.3.3 |
| apache | http_server | 1.0.2 |
| apache | http_server | 2.0.9 |
| apache | http_server | 1.3.18 |
| apache | http_server | 1.3.28 |
| apache | http_server | 2.0.39 |
| apache | http_server | 2.0.28 |
| apache | http_server | 1.3.20 |
| apache | http_server | 2.0.35 |
| apache | http_server | 1.3.17 |
| apache | http_server | 1.3.9 |
| apache | http_server | 2.0 |
| apache | http_server | 2.0.48 |
| apache | http_server | 1.3.7 |
| apache | http_server | 1.0.5 |
| apache | http_server | 1.3.22 |
| apache | http_server | 2.0.38 |
| apache | http_server | 1.3.27 |
| apache | http_server | 1.3.23 |
| apache | http_server | 1.1 |
| apache | http_server | 1.3.26 |
| apache | http_server | 2.0.45 |
| apache | http_server | 2.0.41 |
| apache | http_server | 1.3.4 |
| apache | http_server | 1.3.24 |
| apache | http_server | 1.1.1 |
| apache | http_server | 1.3.14 |
| apache | http_server | 2.0.37 |
| apache | http_server | 1.3.25 |
| apache | http_server | 1.3.1 |
| apache | http_server | 1.2 |
| apache | http_server | 1.0 |
| apache | http_server | 1.3.12 |
| apache | http_server | 1.3 |
| apache | http_server | 1.3.29 |
| apache | http_server | 2.0.43 |
| apache | http_server | 2.0.44 |
| apache | http_server | 2.0.40 |
| apache | http_server | 2.0.42 |
| apache | http_server | 1.2.5 |
| apache | http_server | 1.3.19 |
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| open_group | cde_common_desktop_environment | 1.2 |
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| open_group | cde_common_desktop_environment | 2.1 |
| xi_graphics | dextop | 2.1 |
| ibm | aix | 5.2 |
| open_group | cde_common_desktop_environment | 2.0 |
| open_group | cde_common_desktop_environment | 1.1 |
| open_group | cde_common_desktop_environment | 2.1.20 |
| xi_graphics | dextop | 3.0 |
| open_group | cde_common_desktop_environment | 1.0.2 |
| open_group | cde_common_desktop_environment | 1.0.1 |
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-88,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.5 |
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 1.3.27 |
| apache | http_server | 1.3.28 |
| ibm | http_server | 1.3.26.1 |
| ibm | http_server | 1.3.26.2 |
| apache | http_server | 1.3.26 |
| apache | http_server | 1.3.31 |
| apache | http_server | 1.3.29 |
| openbsd | openbsd | 3.5 |
| ibm | http_server | 1.3.28 |
| openbsd | openbsd | * |
| ibm | http_server | 1.3.26 |
| hp | webproxy | 2.0 |
| sgi | propack | 2.4 |
| hp | webproxy | 2.1 |
| hp | virtualvault | 11.0.4 |
| hp | vvos | 11.04 |
| openbsd | openbsd | 3.4 |
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| avaya | s8700 | r2.0.0 |
| trustix | secure_linux | 1.5 |
| ibm | http_server | 2.0.42.1 |
| ibm | http_server | 2.0.42.2 |
| avaya | converged_communications_server | 2.0 |
| trustix | secure_linux | 2.1 |
| ibm | http_server | 2.0.42 |
| apache | http_server | 2.0.47 |
| ibm | http_server | 2.0.47 |
| apache | http_server | 2.0.48 |
| trustix | secure_linux | 2.0 |
| apache | http_server | 2.0.49 |
| ibm | http_server | 2.0.47.1 |
| avaya | s8500 | r2.0.0 |
| avaya | s8300 | r2.0.0 |
| gentoo | linux | 1.4 |
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
| ibm | aix | 5.2 |
LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.2 |
acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | acprunner | 1.2.5.0 |
Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.5.0 |
WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_edge_server_caching_proxy | 5.0.2 |
| ibm | websphere_caching_proxy_server | 5.0.2 |
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1 |
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 1.3.22 |
| apache | http_server | 1.3.27 |
| apache | http_server | 1.3.23 |
| hp | virtualvault | 4.7 |
| apache | http_server | 1.3.6 |
| apache | http_server | 1.3.26 |
| avaya | intuity_audix_lx | * |
| hp | webproxy | a.02.10 |
| openbsd | openbsd | 3.5 |
| apache | http_server | 1.3.4 |
| sco | openserver | 5.0.6 |
| apache | http_server | 1.3.24 |
| openbsd | openbsd | current |
| apache | http_server | 1.3.11 |
| avaya | communication_manager | 2.0.1 |
| apache | http_server | 1.3.14 |
| ibm | http_server | 1.3.19 |
| avaya | mn100 | * |
| apache | http_server | 1.3.3 |
| apache | http_server | 1.3.25 |
| avaya | modular_messaging_message_storage_server | 1.1 |
| apache | http_server | 1.3.1 |
| openbsd | openbsd | 3.4 |
| hp | webproxy | a.02.00 |
| apache | http_server | 1.3.12 |
| apache | http_server | 1.3.18 |
| apache | http_server | 1.3.28 |
| avaya | communication_manager | 1.1 |
| apache | http_server | 1.3 |
| hp | virtualvault | 4.5 |
| apache | http_server | 1.3.29 |
| hp | virtualvault | 4.6 |
| avaya | network_routing | * |
| avaya | communication_manager | 2.0 |
| sun | solaris | 8.0 |
| apache | http_server | 1.3.20 |
| apache | http_server | 1.3.17 |
| apache | http_server | 1.3.9 |
| sun | sunos | 5.8 |
| apache | http_server | 1.3.19 |
| avaya | modular_messaging_message_storage_server | 2.0 |
| apache | http_server | 1.3.7 |
| apple | apache_mod_digest_apple | * |
| avaya | communication_manager | 1.3.1 |
| sun | solaris | 9.0 |
| sco | openserver | 5.0.7 |
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | net.data | 7.0 |
| ibm | net.data | 7.2 |
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.0.1 |
| ibm | lotus_domino | 6.5.2 |
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| engenio | storage_controller | 4884 |
| brocade | silkworm_fiber_channel_switch | 2050 |
| brocade | silkworm | 3850 |
| ibm | ds4100 | * |
| brocade | silkworm | 3250 |
| brocade | silkworm | 3900 |
| broadcom | fabric_operating_system | 2.1.2 |
| engenio | storage_controller | 2822 |
| storagetek | d280 | * |
| brocade | silkworm | 3800 |
| brocade | silkworm_fiber_channel_switch | 2040 |
| brocade | silkworm | 3200 |
| engenio | storage_controller | 2882 |
| broadcom | fabric_operating_system | 3.1 |
| brocade | silkworm_fiber_channel_switch | 2010 |
| broadcom | fabric_operating_system | 2.2 |
| engenio | storage_controller | 5884 |
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ip_call_center_express_standard | 3.0 |
| ibm | mcs-7835i-3.0 | * |
| cisco | call_manager | 3.1(3a) |
| ibm | x330 | 8674 |
| ibm | director_agent | 3.11 |
| ibm | x330 | 8654 |
| cisco | internet_service_node | * |
| ibm | mcs-7815-1000 | * |
| cisco | personal_assistant | 1.3(4) |
| cisco | ip_interactive_voice_response | 3.0 |
| cisco | conference_connection | 1.1(1) |
| cisco | ip_call_center_express_enhanced | 3.0 |
| cisco | call_manager | 4.0 |
| ibm | x345 | * |
| cisco | emergency_responder | 1.1 |
| cisco | personal_assistant | 1.3(3) |
| cisco | call_manager | 1.0 |
| ibm | mcs-7835i-2.4 | * |
| ibm | x342 | * |
| cisco | call_manager | 3.0 |
| cisco | personal_assistant | 1.4(2) |
| cisco | call_manager | 3.3(3) |
| cisco | call_manager | 2.0 |
| ibm | mcs-7815i-2.0 | * |
| cisco | personal_assistant | 1.3(2) |
| cisco | personal_assistant | 1.3(1) |
| ibm | director_agent | 2.2 |
| ibm | x340 | * |
| cisco | call_manager | 3.1 |
| cisco | call_manager | 3.3 |
| cisco | conference_connection | 1.2 |
| cisco | call_manager | 3.2 |
| cisco | personal_assistant | 1.4(1) |
| cisco | call_manager | 3.1(2) |
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ip_call_center_express_standard | 3.0 |
| ibm | mcs-7835i-3.0 | * |
| cisco | call_manager | 3.1(3a) |
| ibm | x330 | 8674 |
| ibm | director_agent | 3.11 |
| ibm | x330 | 8654 |
| cisco | internet_service_node | * |
| ibm | mcs-7815-1000 | * |
| cisco | personal_assistant | 1.3(4) |
| cisco | ip_interactive_voice_response | 3.0 |
| cisco | conference_connection | 1.1(1) |
| cisco | ip_call_center_express_enhanced | 3.0 |
| cisco | call_manager | 4.0 |
| ibm | x345 | * |
| cisco | emergency_responder | 1.1 |
| cisco | personal_assistant | 1.3(3) |
| cisco | call_manager | 1.0 |
| ibm | mcs-7835i-2.4 | * |
| ibm | x342 | * |
| cisco | call_manager | 3.0 |
| cisco | personal_assistant | 1.4(2) |
| cisco | call_manager | 3.3(3) |
| cisco | call_manager | 2.0 |
| ibm | mcs-7815i-2.0 | * |
| cisco | personal_assistant | 1.3(2) |
| cisco | personal_assistant | 1.3(1) |
| ibm | director_agent | 2.2 |
| ibm | x340 | * |
| cisco | call_manager | 3.1 |
| cisco | call_manager | 3.3 |
| cisco | conference_connection | 1.2 |
| cisco | call_manager | 3.2 |
| cisco | personal_assistant | 1.4(1) |
| cisco | call_manager | 3.1(2) |
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_extended_parallel_server | 8.40_uc1 |
Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | parallel_environment | 3.2 |
| ibm | parallel_environment | 4.1 |
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 6.5.2 |
Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 6.5.2 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_extended_parallel_server | 8.40_uc2 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_extended_parallel_server | 8.40_uc1 |
Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3.3 |
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | trading_partner_interchange | * |
| jetty | jetty_http_server | 4.2.11 |
| ca | unicenter_web_services_distributed_management | * |
| jetty | jetty_http_server | 4.2.7 |
| jetty | jetty_http_server | 4.2.18 |
| jetty | jetty_http_server | 4.2.6 |
| jetty | jetty_http_server | 4.2.4 |
| jetty | jetty_http_server | 3.1.7 |
| jetty | jetty_http_server | 4.1.0 |
| jetty | jetty_http_server | 4.2.12 |
| jetty | jetty_http_server | 4.2.14 |
| jetty | jetty_http_server | 4.2.5 |
| jetty | jetty_http_server | 4.2.16 |
| jetty | jetty_http_server | 4.2.9 |
| jetty | jetty_http_server | 3.1.6 |
| jetty | jetty_http_server | 4.1.0_rc4 |
| jetty | jetty_http_server | 4.2.15 |
| ibm | trading_partner_interchange | 4.2.1 |
| jetty | jetty_http_server | 4.1.1 |
| jetty | jetty_http_server | 4.2.17 |
| jetty | jetty_http_server | 4.2.19 |
Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.uc1 |
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_extended_parallel_server | 8.40_uc2 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_extended_parallel_server | 8.40_uc1 |
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 3.2.2 |
| ibm | tivoli_directory_server | * |
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_identity_manager_solution | 5.1 |
| ibm | tivoli_configuration_manager_for_atm | 2.1 |
| ibm | tivoli_access_manager_for_e-business | 3.9 |
| ibm | tivoli_access_manager_for_e-business | 5.1 |
| ibm | tivoli_secureway_policy_director | 3.8 |
| ibm | websphere_everyplace_server | 2.1.3 |
| ibm | tivoli_configuration_manager | 4.2 |
| ibm | websphere_everyplace_server | 2.1.4 |
| ibm | websphere_everyplace_server | 2.1.5 |
| ibm | tivoli_access_manager_for_e-business | 4.1 |
The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | egatherer | 2.0.0.16 |
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 4.3.3 |
The server in IBM Tivoli Storage Manager (TSM) 4.2.x on MVS, 5.1.9.x before 5.1.9.1, 5.1.x before 5.1.10, 5.2.2.x before 5.2.2.3, 5.2.x before 5.2.3, 5.3.x before 5.3.0, and 6.x before 6.1, when the HTTP communication method is enabled, allows remote attackers to cause a denial of service (daemon crash or hang) via unspecified HTTP traffic, as demonstrated by the IBM port scanner 1.3.1.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 4.2.3 |
| ibm | tivoli_storage_manager | 4.2.4 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 5.2.0 |
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 4.2 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 5.2.2 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 4.2.2 |
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sgi | propack | 3.0 |
| redhat | fedora_core | core_3.0 |
| trustix | secure_linux | 2.1 |
| suse | suse_linux | 8.1 |
| redhat | enterprise_linux | 3.0 |
| larry_wall | perl | 5.8.4.2.3 |
| trustix | secure_linux | 2.0 |
| ibm | aix | 5.3 |
| larry_wall | perl | 5.8.4 |
| larry_wall | perl | 5.8.4.1 |
| suse | suse_linux | 8.0 |
| larry_wall | perl | 5.8.4.5 |
| trustix | secure_linux | 1.5 |
| ibm | aix | 5.2 |
| larry_wall | perl | 5.8.4.2 |
| ubuntu | ubuntu_linux | 4.1 |
| suse | suse_linux | 9.2 |
| larry_wall | perl | 5.8.4.4 |
| larry_wall | perl | 5.8.4.3 |
| larry_wall | perl | 5.8.3 |
| redhat | enterprise_linux_desktop | 3.0 |
| larry_wall | perl | 5.8.1 |
| suse | suse_linux | 9.1 |
| larry_wall | perl | 5.8.0 |
| trustix | secure_linux | 2.2 |
| suse | suse_linux | 8.2 |
| suse | suse_linux | 9.0 |
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2 |
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.2 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 6.0 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0 |
Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 4.2 |
| ibm | hardware_management_console | 4.1 |
AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| powerterm | interconnect | * |
| mochasoft | tn5250 | * |
| bosanova | launcher400 | * |
| ibm | client_access | * |
AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | 5.2 |
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 6.5.1 |
| ibm | lotus_domino_server | 6.0.3 |
The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | iseries_as_400 | 4.3 |
Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 6.5.4 |
| ibm | lotus_domino_server | 6.0.5 |
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.1.0.4 |
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | iseries_as_400 | * |
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0.10 |
| ibm | aix | 5.2.0.54 |
| ibm | aix | 5.2.0.50 |
| ibm | aix | 5.3.0.20 |
Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | r510 |
| ibm | os_400 | r520 |
| ibm | os_400 | r530 |
By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | iseries_as_400 | * |
HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 6.5.2 |
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.0.1 |
| ibm | lotus_domino | 6.5.2 |
Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 6.5.2 |
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0 |
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1.8a |
| ibm | db2 | 8.2.2 |
| ibm | db2 | 8.1.6 |
| ibm | db2 | 8.1.5 |
| ibm | db2 | 8.2.0 |
| ibm | db2 | 8.2.1 |
| ibm | db2 | 8.1.7 |
| ibm | db2 | 8.1.9 |
| ibm | db2 | 8.1.4 |
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0 |
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 4.1.1 |
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 5.0 |
IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 7.0.0 |
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| autonomy | keyview_filter_sdk | * |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.5 |
| autonomy | keyview_export_sdk | * |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| autonomy | keyview_viewer_sdk | * |
| ibm | lotus_notes | 6.0.4 |
Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| autonomy | keyview_filter_sdk | * |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.5 |
| autonomy | keyview_export_sdk | * |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| autonomy | keyview_viewer_sdk | * |
| ibm | lotus_notes | 6.0.4 |
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.0.2.1 |
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.1.3 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.1.2 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 6.0.4 |
| ibm | lotus_domino | 6.0.1.1 |
| ibm | lotus_domino | 6.5.3.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.2.1 |
| ibm | lotus_domino | 6.0.2.2 |
| ibm | lotus_domino | 6.0.1 |
Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 6.12 |
| ibm | rational_clearquest | 5.20 |
| ibm | rational_clearquest | 6.10 |
| ibm | rational_clearquest | 5.00 |
| ibm | rational_clearquest | 6.00 |
| ibm | rational_clearquest | 6.13 |
| ibm | rational_clearquest | 6.14 |
| ibm | rational_clearquest | 6.15 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.2 |
Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 6.0 |
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager | 8.2 |
INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager | 8.2 |
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_database_server | 9.40.uc1 |
| ibm | informix_dynamic_database_server | 9.40.uc3 |
| ibm | informix_dynamic_database_server | 9.40.uc2 |
| ibm | informix_dynamic_database_server | 9.3 |
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0 |
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie Reviewer, and (6) Movie Review fields to (d) TechnologySamples/MovieReview2_1.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0 |
IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 6.5.4.3 |
| ibm | lotus_domino | 6.5.4.1 |
| ibm | lotus_domino | 6.5.4.2 |
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0 |
IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.1.0.4 |
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 7.0 |
| ibm | db2_universal_database | 8.1 |
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H | 1.8 | 5.2 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 7.2 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 7.1 |
| ibm | db2_universal_database | 8.1 |
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_domino_enterprise_server | 6.5.4 |
Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_domino_enterprise_server | 6.5.4 |
Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_domino_enterprise_server | 6.5.4 |
Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_domino_enterprise_server | 6.5.4 |
Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino_enterprise_server | 6.5.2 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_domino_enterprise_server | 6.5.4 |
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_ml03 |
Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.0.0 |
| ibm | tivoli_access_manager_for_e-business | 5.1.0.10 |
IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 7.0 |
Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_inotes_client | 6.5.4 |
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_inotes_client | 7.0 |
| ibm | lotus_domino_inotes_client | 6.5.4 |
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0 |
Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1.4 |
Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.1l |
| ibm | aix | 5.1 |
| ibm | aix | 5.3.0.10 |
| ibm | aix | 5.2 |
| ibm | aix | 5.3.0.20 |
| ibm | aix | 5.3_ml03 |
| ibm | aix | 5.3.0 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 5.2.0.54 |
| ibm | aix | 5.2.2 |
| ibm | aix | 5.2.0.50 |
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_systems_manager | 3.1 |
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 4.0.3 |
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.0 |
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2 |
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.2.5 |
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.0.2.1 |
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 5.1.0.4 |
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.0.1 |
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.2.5 |
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.0.1 |
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.0.1 |
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.1 |
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.1.4 |
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.1.4 |
Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other products, allows unauthorized users to gain access to privileged commands via unknown vectors, probably related to incorrect capabilities with the audit role.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | network_appliance_data_ontap | 7.0 |
| ibm | network_appliance_data_ontap | 7.0.4p8d9 |
| ibm | network_appliance_data_ontap | 7.1 |
| ibm | network_appliance_data_ontap | 7.2 |
| ibm | network_appliance_data_ontap | 7.1.0.1 |
IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain the list of original recipients.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.0 |
Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, when running on Windows, allows remote attackers to execute arbitrary code via a long username.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xc7 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_database_server | 9.40.tc7 |
| ibm | informix_dynamic_database_server | 10.00.tc5 |
| ibm | informix_dynamic_database_server | 10.00.tc4 |
| ibm | informix_dynamic_database_server | 9.40.tc8 |
The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows local users to cause a denial of service (crash) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
Multiple buffer overflows in IBM Informix Dynamic Server (IDS) before 9.40.TC6 and 10.00 before 10.00.TC3 allow remote authenticated users to execute arbitrary code via (1) the getname function, as used by (a) _sq_remview, (b) _sq_remproc, (c) _sq_remperms, (d) _sq_distfetch, and (e) _sq_dcatalog; and the (2) SET DEBUG FILE, (3) IFX_FILE_TO_FILE, (4) FILETOCLOB, (5) LOTOFILE, and (6) DBINFO functions (product defect IDs 171649, 171367, 171387, 171391, 171906, 172179).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_database_server | 9.40.tc1 |
| ibm | informix_dynamic_database_server | 10.00.tc2 |
| ibm | informix_dynamic_database_server | 9.40.uc1 |
| ibm | informix_dynamic_database_server | 9.40.tc2 |
| ibm | informix_dynamic_database_server | 9.40.tc4 |
| ibm | informix_dynamic_database_server | 9.40.tc5 |
| ibm | informix_dynamic_database_server | 9.40.uc3 |
| ibm | informix_dynamic_database_server | 9.40.uc2 |
| ibm | informix_dynamic_database_server | 10.00.tc1 |
| ibm | informix_dynamic_database_server | 9.3 |
| ibm | informix_dynamic_database_server | 9.40.tc3 |
IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xc7 |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_database_server | 9.40.tc7 |
| ibm | informix_dynamic_database_server | 10.00.tc5 |
| ibm | informix_dynamic_database_server | 10.00.tc4 |
| ibm | informix_dynamic_database_server | 9.40.tc8 |
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_database_server | 9.4 |
| ibm | informix_dynamic_database_server | 9.40.uc1 |
| ibm | informix_dynamic_database_server | 9.40.xc7 |
| ibm | informix_dynamic_database_server | 9.40.tc5 |
| ibm | informix_dynamic_database_server | 9.40.uc5 |
| ibm | informix_dynamic_database_server | 10.0 |
| ibm | informix_dynamic_database_server | 9.40.uc3 |
| ibm | informix_dynamic_database_server | 10.0_xc3 |
| ibm | informix_dynamic_database_server | 9.40.uc2 |
| ibm | informix_dynamic_database_server | 7.31_.xd8 |
| ibm | informix_dynamic_database_server | 7.3 |
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
| ibm | informix_dynamic_server | 7.31 |
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 10.0.tc1 |
| ibm | informix_dynamic_server | 9.40.tc5 |
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.2.1 |
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.2.1 |
Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code via a long filename parameter to the RunEgatherer method.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | egatherer | 2.0.16 |
| ibm | egatherer | 2.42.243 |
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1.8a |
| ibm | db2 | 8.1.7b |
| ibm | db2 | 8.1 |
| ibm | db2 | 8.10 |
| ibm | db2 | 8.2 |
| ibm | db2 | 8.0 |
| ibm | db2 | 8.1.8 |
| ibm | db2 | 8.1.7 |
| ibm | db2 | 8.1.6c |
| ibm | db2 | 8.1.4 |
| ibm | db2 | 8.1.9a |
| ibm | db2 | 8.1.6 |
| ibm | db2 | 8.12 |
| ibm | db2 | 8.1.5 |
| ibm | db2 | 8.1.9 |
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.1 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | * |
Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | * |
IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | * |
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_access | 7.0.1 |
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 7.0.1 |
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inventory_scout | 2.2.0.3 |
| ibm | inventory_scout | 2.2.0.2 |
| ibm | inventory_scout | 2.2.0.5 |
| ibm | inventory_scout | 2.2.0.7 |
| ibm | inventory_scout | 2.2.0.8 |
| ibm | inventory_scout | 2.2.0.9 |
| ibm | inventory_scout | 2.2.0.0 |
| ibm | inventory_scout | 2.2.0.4 |
| ibm | inventory_scout | 2.2.0.6 |
| ibm | inventory_scout | 2.2.0.1 |
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_security_password_manager | * |
IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.uc_rc1 |
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00 |
| ibm | informix_client_sdk | 2.90 |
| ibm | informix_i-connect | 2.90 |
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00 |
| ibm | informix_client_sdk | 2.90 |
| ibm | informix_i-connect | 2.90 |
Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | * |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 6.0.4 |
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.0.1 |
The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.0.4 |
Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.3 |
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0 |
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0 |
Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value in unspecified messages, a different issue than CVE-2006-5855.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.3 |
IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_host_on-demand | 7.0 |
| ibm | websphere_host_on-demand | 8.0 |
| ibm | websphere_host_on-demand | 9.0 |
| ibm | websphere_host_on-demand | 6.0 |
The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users to obtain the password by listing the process or using other methods.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_identity_manager | 4.6 |
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 5.1.1.4 |
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.15 |
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.12 |
| ibm | db2_universal_database | 8.10 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | v5r3m0 |
Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 5.1.1.4 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | * |
The Image Viewer component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-002 removes a user from an ACL when the user is denied all permissions for an annotation, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-001 does not ensure that the AE Administrator role is present for Site Preferences modifications, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_server | 6.5.1 |
| ibm | lotus_domino_web_server | 6.5.4 |
| ibm | lotus_domino_web_server | 6.0.2_cf2 |
| ibm | lotus_domino_web_server | 6.5.3 |
| ibm | lotus_domino_web_server | 6.0.2 |
| ibm | lotus_domino_web_server | 6.0.3 |
| ibm | lotus_domino_web_server | 6.5.5 |
| ibm | lotus_domino_web_server | 7.0.1 |
| ibm | lotus_domino_web_server | 6.5.0 |
| ibm | lotus_domino_web_server | 6.0.5 |
| ibm | lotus_domino_web_server | 6.5.2 |
| ibm | lotus_domino_web_server | 6.0.1 |
| ibm | lotus_domino_web_server | 6.0 |
| ibm | lotus_domino_web_server | 6.0.4 |
| ibm | lotus_domino_web_server | 7.0 |
| ibm | lotus_domino_web_server | 7.0.2 |
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 7.0.1 |
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | r530 |
| ibm | os_400 | r535 |
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 5.0 |
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.0 |
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 8.1.4 |
| ibm | db2_universal_database | 8.1.9a |
| ibm | db2_universal_database | 8.12 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 8.10 |
| ibm | db2_universal_database | 8.1.6 |
| ibm | db2_universal_database | 8.1.7 |
| ibm | db2_universal_database | 8.1.5 |
| ibm | db2_universal_database | 8.1.8a |
| ibm | db2_universal_database | 8.1.6c |
| ibm | db2_universal_database | 8.1.9 |
| ibm | db2_universal_database | 9.1 |
| ibm | db2_universal_database | 8.1.7b |
| ibm | db2_universal_database | 8.1 |
| ibm | db2_universal_database | 8.1.8 |
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1.8a |
| ibm | db2 | 8.1.7b |
| ibm | db2 | 8.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 8.1.8 |
| ibm | db2 | 8.1.7 |
| ibm | db2 | 8.1.6c |
| ibm | db2 | 8.1.4 |
| ibm | db2 | 8.1.9a |
| ibm | db2 | 9.1 |
| ibm | db2 | 8.1.6 |
| ibm | db2 | 8.1.5 |
| ibm | db2 | 8.1.9 |
Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1.8a |
| ibm | db2 | 8.1.7b |
| ibm | db2 | 8.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 8.1.8 |
| ibm | db2 | 8.1.7 |
| ibm | db2 | 8.1.6c |
| ibm | db2 | 8.1.4 |
| ibm | db2 | 8.1.9a |
| ibm | db2 | 9.1 |
| ibm | db2 | 8.1.6 |
| ibm | db2 | 8.1.5 |
| ibm | db2 | 8.1.9 |
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 9.1 |
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.0 |
| ibm | db2 | 8.2 |
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.0 |
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 7.0.1 |
Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory allocation.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 7.0.1 |
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
| ibm | lotus_sametime | 7.5 |
Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_os_deployment | 5.1.0.116 |
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_service_manager | 4.1 |
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 7.0 |
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring_express | 6.1.0 |
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | * |
Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2.0 |
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 1.0 |
SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 1.0 |
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | totalstorage_ds400 | 4.15 |
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-369,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_os_deployment | 5.1.0.2 |
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2.0 |
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.1 |
Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.5.6 |
IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | v4r3 |
| ibm | os_400 | r520 |
| ibm | os_400 | v4r2m0 |
| ibm | os_400 | v4r5 |
| ibm | os_400 | v5r1 |
| ibm | os_400 | v4r4 |
| ibm | os_400 | v5r3m0 |
| ibm | os_400 | v5r2m0 |
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | * |
Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_ips_gx5008 | 1.5 |
| ibm | proventia_network_ips_gx5108 | 1.3 |
PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_ips_gx5008 | 1.5 |
| ibm | proventia_network_ips_gx5108 | 1.3 |
Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2.0 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-134,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 6.0 |
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | * |
Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.0.1 |
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.0 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 9.1 |
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino_web_access | 6.5.1 |
| ibm | domino_web_access | 6.5.4 |
| ibm | domino_web_access | 6.5.5 |
| ibm | domino_web_access | 6.0.1 |
| ibm | domino_web_access | 6.0.1.1 |
| ibm | domino_web_access | 7.0 |
| ibm | domino_web_access | 6.5.3 |
| ibm | domino_web_access | 6.0.2 |
| ibm | domino_web_access | 7.0.1 |
| ibm | domino_web_access | 6.0.3 |
| ibm | domino_web_access | 6.0.5 |
| ibm | domino_web_access | 6.0.4 |
| ibm | domino_web_access | 6.0 |
| ibm | domino_web_access | 6.5.2 |
| ibm | lotus_domino_web_access | 7.0.1 |
| ibm | domino_web_access | 6.5 |
| ibm | lotus_domino_web_access | 7.0.34.1 |
Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | * |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.2 |
IBM SurePOS 500 has (1) a default password of "12345" for the manager and (2) blank default passwords for operator accounts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | surepos_500 | * |
Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2 |
Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2 |
Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.9 |
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | 5.4.1.1 |
| ibm | tivoli_storage_manager_client | 5.1.8.0 |
| ibm | tivoli_storage_manager_client | 5.3 |
| ibm | tivoli_storage_manager_client | 5.1 |
| ibm | tivoli_storage_manager_client | 5.4 |
| ibm | tivoli_storage_manager_client | 5.2 |
| ibm | tivoli_storage_manager_client | 5.2.5.1 |
| ibm | tivoli_storage_manager_client | 5.3.5.2 |
Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | * |
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 6.12 |
| ibm | rational_clearquest | 5.20 |
| ibm | rational_clearquest | 5.00 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 6.00 |
| ibm | rational_clearquest | 6.16 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 6.13 |
| ibm | rational_clearquest | 6.14 |
| ibm | rational_clearquest | 6.15 |
| ibm | rational_clearquest | 7.0.0.1 |
Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority header; (10) a long string at the beginning of an RFC2047 encoded-word in a header; (11) a long text string in an RFC2047 encoded-word in a header; or (12) a long Subject header, related to creation of an associated filename.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| autonomy | keyview | 10.3.0.0 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 6.0 |
Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| symantec | mail_security | 5.0.1 |
| autonomy | keyview | 10.3.0.0 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 7.0.2 |
| symantec | mail_security | 5.0.0 |
| activepdf | docconverter | 3.8.2_.5 |
| ibm | lotus_notes | 6.5 |
| activepdf | docconverter | 3.8.4.0 |
| symantec | mail_security_appliance | 5.0 |
| ibm | lotus_notes | 6.0 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 7.5 |
| autonomy | keyview | 2.0.0.2 |
kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted .ag file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| symantec | mail_security | 5.0.1 |
| ibm | lotus_notes | 8.0 |
| autonomy | keyview | * |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.0 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 5.0.0 |
| ibm | lotus_notes | 8.0.1 |
| symantec | mail_security | * |
Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 5.1.1.4 |
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | * |
Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | thinkvantage_tpm | * |
CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large number of idle connections.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | * |
| ibm | director | 3.1 |
| ibm | director | 5.10.3 |
| ibm | director | 5.10 |
IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | * |
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | 8 |
| ibm | db2_universal_database | 9.1 |
The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenticated users to gain privileges and obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.5.6 |
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 6.5.6 |
Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 9.0 |
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | 8 |
| ibm | db2_universal_database | 9.1 |
Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_continuous_data_protection_for_files | 3.1.0 |
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| autonomy | keyview_filter_sdk | * |
| symantec | mail_security | 5.0.1 |
| ibm | lotus_notes | * |
| autonomy | keyview_export_sdk | * |
| symantec | mail_security | 5.0.0.24 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 5.0.0 |
| activepdf | docconverter | 3.8.2_.5 |
| autonomy | keyview_viewer_sdk | * |
| symantec | mail_security | 7.5 |
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| autonomy | keyview_filter_sdk | * |
| symantec | mail_security | 5.0.1 |
| ibm | lotus_notes | * |
| autonomy | keyview_export_sdk | * |
| symantec | mail_security | 5.0.0.24 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 5.0.0 |
| activepdf | docconverter | 3.8.2_.5 |
| autonomy | keyview_viewer_sdk | * |
| symantec | mail_security | 7.5 |
Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | * |
Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.1.1.4 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_service_desk | 6.2 |
Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | * |
Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 10.00.TC3TL and 11.10.TB4TL on Windows allows attackers to cause a denial of service (application crash) via unspecified SQ_ONASSIST requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00.tc3tl |
| ibm | informix_dynamic_server | 11.10.tb4tl |
Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| symantec | mail_security | 5.0.1 |
| autonomy | keyview | 10.3.0.0 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 7.0.2 |
| symantec | mail_security | 5.0.0 |
| ibm | lotus_notes | 6.5 |
| activepdf | docconverter | 3.8.4.0 |
| symantec | mail_security_appliance | 5.0 |
| ibm | lotus_notes | 6.0 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 7.5 |
| autonomy | keyview | 2.0.0.2 |
Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0 |
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool_security_manager | 1.3.0 |
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 6.1.3 |
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers to gain privileges via "some HMC commands."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 3.3.7 |
Cross-site scripting (XSS) vulnerability in the WebRunMenuFrame page in the online meeting center template in IBM Lotus Sametime before 8.0 allows remote attackers to inject arbitrary web script or HTML via the URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 7.3.2.0 |
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool_security_manager | 1.3.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_express | * |
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_express | * |
Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, related to "scripting."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager_toolkit | 8.3 |
Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.0 |
IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | * |
Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.11 |
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 8.0 |
Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.2.0 |
The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 7.0.3 |
| autonomy | keyview | * |
| ibm | lotus_notes | 7.0.2 |
Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 7.0.1 |
Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_express | * |
Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 7.5 |
| ibm | lotus_sametime | 7.5.1 |
onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.0 |
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00 |
Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 5.1.1.4 |
Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_os_deployment | * |
Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_business_modeler | 6.0.2_1 |
IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_service_manager | 4.1.1 |
Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 7.3.2.0 |
Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.3 |
Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | v5r3m0 |
| ibm | os_400 | v5r4m0 |
IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.2_fixpack15 |
Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.2_fixpack15 |
Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.2_fixpack15 |
Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.2 |
| ibm | db2 | 9.5 |
Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_edge_server | 6.1 |
| ibm | websphere_edge_server | 6.0.1 |
| ibm | websphere_edge_server | 5.1 |
| ibm | websphere_edge_server | 6.0.2 |
| ibm | websphere_edge_server | 5.1.1 |
| ibm | websphere_edge_server | 6.0 |
Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 7.31.xd9 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xd8 |
| ibm | informix_dynamic_server | 11.10.xc2 |
| ibm | informix_dynamic_server | 10.0.xc4 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
| ibm | informix_dynamic_server | 9.3 |
| ibm | informix_dynamic_server | 10.00.xc7w1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 7.3 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 7.31.xd8 |
| ibm | informix_dynamic_server | 9.40_xc7 |
IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | * |
| ibm | informix_storage_manager | - |
Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.0.2 |
| ibm | lotus_quickr | 8.0 |
Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickplace | 7.0 |
IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.0 |
Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 7.31.xd9 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xd8 |
| ibm | informix_dynamic_server | 11.10.xc2 |
| ibm | informix_dynamic_server | 10.0.xc4 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.4 |
| ibm | informix_dynamic_server | 9.3 |
| ibm | informix_dynamic_server | 10.00.xc7w1 |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 7.3 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 7.31.xd8 |
| ibm | informix_dynamic_server | 9.40_xc7 |
Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| autonomy | keyview | 10.3.0.0 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 6.0 |
| autonomy | keyview | 2.0.0.2 |
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 5.3 |
| ibm | websphere_mq | 6 |
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr_server | 8.0 |
Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 7.0.2 |
Untrusted search path vulnerability in man in IBM AIX 6.1.0 allows local users to execute arbitrary code via a malicious program in the man directory.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1.0 |
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.0.2 |
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.0.2 |
MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 5.1 |
| ibm | websphere_mq | 5.3 |
| ibm | websphere_mq | 5.3.1 |
The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 5.2 |
Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privilege.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager | * |
Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-134,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 06.00.1018 |
Uncontrolled array index in IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large value in a certain 32-bit field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 06.00.1018 |
IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a packet with an 0x11 value in a certain "type" field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | * |
IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of memory to allocate, which allows remote attackers to cause a denial of service (daemon exit) via a packet with a large value in this field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | * |
Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes before 8.0, might allow user-assisted remote attackers to execute arbitrary code via an e-mail message with a crafted Text mail (MIME) attachment.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 8.0 |
| autonomy | keyview | * |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 8.0.1 |
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_expeditor_client | 6.1.2 |
| ibm | lotus_symphany | * |
| ibm | lotus_expeditor_client | 6.1.1 |
Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-772,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_build_forge | 7.0.2 |
IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0.2 |
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0 |
Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_web_server | 7.0.1 |
| ibm | lotus_domino_web_server | * |
| ibm | lotus_domino_web_server | 7.0 |
| ibm | lotus_domino_web_server | 7.0.2 |
| ibm | lotus_domino_web_server | 7.0.3 |
Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
| ibm | lotus_sametime | 7.5.1 |
Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.1.0.11 |
Buffer overflow in the BrSmRcvAndCheck function in the RCHMGR module on IBM OS/400 V5R4M0, V5R4M5, and V6R1M0 allows local users to cause a denial of service (task halt and main storage dump) via unspecified vectors involving the running of diagnostics on a modem port. NOTE: there might be limited attack scenarios.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | os_400 | v6r1m0 |
| ibm | os_400 | v5r4m5 |
| ibm | os_400 | v5r4m0 |
Heap-based buffer overflow in the IBM AFP Viewer Plug-in 2.0.7.1 and 3.2.1.1 allows remote attackers to execute arbitrary code via a long SRC property value. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | afp_viewer_plug-in | 3.2.1.1 |
| ibm | afp_viewer_plug-in | 2.0.7.1 |
Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulnerability," although there are likely scenarios in which a user is allowed to make administrative LDAP requests but does not have the privileges to stop the server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.1 |
Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer and IBM System Storage N series Gateway, have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | data_ontap | * |
Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo | 4.1 |
| ibm | maximo | 5.2 |
Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 5.1.1.18 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.1.1.4 |
Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 5.1.1.18 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.1.1.4 |
IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 5.1.0.4 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 5.1.0.2 |
| ibm | websphere_portal | 5.1.0.3 |
| ibm | websphere_portal | 5.1.0.5 |
| ibm | websphere_portal | 5.1.0.0 |
| ibm | websphere_portal | 5.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1 |
Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 9.1 |
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.1 |
Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | 9.1 |
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.1 |
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 8 |
| ibm | db2_universal_database | 8.0 |
| ibm | db2_universal_database | 9.1 |
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.1 |
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.1 |
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lenovo_7cetb5ww | 2.05 |
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.0 |
| ibm | db2 | * |
IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
| ibm | db2 | 8.2 |
| ibm | db2 | * |
Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | * |
| ibm | db2_universal_database | 8.2 |
swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.1.0.11 |
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 5.1.1.18 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 5.1.1.4 |
Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 5.1.1.18 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.19 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.13 |
IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool_webtop | 2.1.0 |
The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | zseries | * |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a "nonstandard URL argument" to the OpenDocument command. NOTE: due to lack of details from the vendor, it is not clear whether this is a vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager_express | 5.3.7.3 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager_express | 5.3.3.0 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager_express | 5.3 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager_express | 5.3.6.4 |
Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.2 |
| symantec | mail_security | 5.0.1 |
| symantec | mail_security | 5.0.11 |
| symantec | mail_security | 5.0.1.181 |
| ibm | lotus_notes | 7.0.2 |
| symantec | mail_security | 5.0.0 |
| autonomy | keyview_export_sdk | 2.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 6.5.2 |
| symantec | data_loss_prevention_endpoint_agents | 8.1 |
| symantec | data_loss_prevention_detection_servers | 7.0 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 5.0.3 |
| symantec | altiris_deployment_solution | * |
| autonomy | keyview_filter_sdk | 10 |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| symantec | data_loss_prevention_detection_servers | 8.0 |
| symantec | enforce | 8.0 |
| ibm | lotus_notes | 6.0.1 |
| symantec | mail_security | 6.0.7 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| symantec | enforce | 8.1 |
| autonomy | keyview_viewer_sdk | 2.0 |
| autonomy | keyview_viewer_sdk | * |
| symantec | mail_security | 5.0.1.189 |
| ibm | lotus_notes | 6.0.4 |
| autonomy | keyview_filter_sdk | * |
| ibm | lotus_notes | 5.0.12 |
| symantec | mail_security | 7.5..4.29 |
| autonomy | keyview_viewer_sdk | 9.2.0 |
| symantec | enforce | 7.0 |
| autonomy | keyview_export_sdk | 10 |
| autonomy | keyview_export_sdk | 9.2.0 |
| symantec | brightmail | 5.0 |
| ibm | lotus_notes | 6.5 |
| symantec | mail_security | 5.0.1.182 |
| ibm | lotus_notes | 6.5.3 |
| autonomy | keyview_filter_sdk | 2.0 |
| symantec | mail_security | 5.0.0.24 |
| autonomy | keyview_viewer_sdk | 10 |
| symantec | mail_security | 5.0 |
| symantec | data_loss_prevention_endpoint_agents | 8.0 |
| symantec | mail_security | 5.0.10 |
| autonomy | keyview_filter_sdk | 10.3 |
| symantec | mail_security | 7.5.3.25 |
| symantec | mail_security | 7.5.5.32 |
| ibm | lotus_notes | 7.0.3 |
| symantec | mail_security | 6.0.6 |
| autonomy | keyview_export_sdk | 10.3 |
| ibm | lotus_notes | 7.0 |
| autonomy | keyview_filter_sdk | 9.2.0 |
| autonomy | keyview_export_sdk | * |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| symantec | data_loss_prevention_detection_servers | 8.1 |
| symantec | mail_security | 5.0.1.200 |
| autonomy | keyview_viewer_sdk | 10.3 |
The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enovia_smarteam | 5 |
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.1 |
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | * |
The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
| ibm | db2 | * |
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | * |
Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli Storage Manager (TSM); and the Backup-Archive client in TSM Express; allows remote attackers to execute arbitrary code by sending a large amount of crafted data to a TCP port.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | * |
| ibm | tivoli_storage_manager_express | * |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | * |
| ibm | lotus_connections | 1.0.2 |
Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | * |
| ibm | lotus_connections | 1.0.2 |
IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | * |
| ibm | lotus_connections | 1.0.2 |
IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | * |
| ibm | lotus_connections | 1.0.2 |
Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.0 |
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | 5.4.1.1 |
| ibm | tivoli_storage_manager_client | 5.3 |
| ibm | tivoli_storage_manager_client | 5.1 |
| ibm | tivoli_storage_manager_client | 5.4 |
| ibm | tivoli_storage_manager_client | 5.1.8.2 |
| ibm | tivoli_storage_manager_client | 5.4.1.2 |
| ibm | tivoli_storage_manager_client | 5.2.5.2 |
| ibm | tivoli_storage_manager_client | 5.3.6.4 |
| ibm | tivoli_storage_manager_express | 5.3.3.0 |
| ibm | tivoli_storage_manager_client | 5.1.8.0 |
| ibm | tivoli_storage_manager_client | 5.3.5.3 |
| ibm | tivoli_storage_manager_client | 5.2.5.3 |
| ibm | tivoli_storage_manager_client | 5.4.1.96 |
| ibm | tivoli_storage_manager_client | 5.2 |
| ibm | tivoli_storage_manager_client | 5.2.5.1 |
| ibm | tivoli_storage_manager_express | 5.3 |
| ibm | tivoli_storage_manager_client | 5.3.6.3 |
| ibm | tivoli_storage_manager_client | 5.3.5.2 |
| ibm | tivoli_storage_manager_express | 5.3.6.4 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus | * |
| ibm | lotus | quickr |
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 3.2.0 |
| ibm | hardware_management_console | 3.3.0 |
Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | metrica_service_assurance_framework | * |
Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded."
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | workplace_content_management | 6.1 |
| ibm | workplace_content_management | 6.0 |
webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of service (crash or hang) via HTTP requests, as demonstrated by a McAfee vulnerability scan.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.0.0.17 |
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 2008 |
| ibm | rational_clearquest | 2007 |
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | * |
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.2 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | * |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | * |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.2 |
enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.2 |
Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.2 |
Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.2 |
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | * |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.0.1.1 |
IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager | 5.1.0.2 |
| ibm | tivoli_provisioning_manager | 5.1.1.1 |
| ibm | tivoli_provisioning_manager | 5.1.1 |
| ibm | tivoli_provisioning_manager | 5.1 |
Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | workplace_for_business_controls_and_reporting | 2.0 |
| ibm | workplace_web_content_management | 6.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x has unknown impact and remote attack vectors. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | workplace_for_business_controls_and_reporting | 2.0 |
| ibm | workplace_web_content_management | 6.0 |
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.5 |
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino_server | 6.0 |
| ibm | lotus_domino_server | 8.0 |
| ibm | lotus_domino_server | 7.0 |
| ibm | lotus_domino_server | 6.5 |
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.9 |
IBM Lotus Quickr 8.1 before 8100.003 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by clicking a download link, aka SPR QCAO7E6AM8.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in the docnote string handling implementation in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, aka SPR JFLD7GZT25.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.6.1.5 |
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | 9.1 |
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | 9.1 |
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 7.3.2.0 |
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | access_support_activex_control | 3.20.284.0 |
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.12 |
| oracle | weblogic_server_component | 10.3 |
| oracle | bea_product_suite | 8.1 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| oracle | bea_product_suite | 10.3 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| oracle | weblogic_server_component | 9.1 |
| ibm | websphere_application_server | 6.0.2.31 |
| oracle | weblogic_server_component | 8.1 |
| ibm | websphere_application_server | 7.0.0.1 |
| oracle | weblogic_server_component | 9.0 |
| ibm | websphere_application_server | 6.0.2.22 |
| oracle | application_server | 10.1.3.4 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| oracle | bea_product_suite | 9.2 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| mono_project | mono | 1.2.6 |
| ibm | websphere_application_server | 6.0.1.15 |
| oracle | application_server | 10.1.2.3 |
| ibm | websphere_application_server | 6.0.2.14 |
| oracle | application_server | 10.1.4.3im |
| mono_project | mono | 1.9 |
| mono_project | mono | 1.2.1 |
| mono_project | mono | 1.2.3 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0 |
| oracle | bea_product_suite | 9.1 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| oracle | bea_product_suite | 10.0 |
| ibm | websphere_application_server | 6.1.0.1 |
| oracle | weblogic_server_component | 10.0 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| mono_project | mono | 1.2.5 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| mono_project | mono | 1.2.4 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| oracle | bea_product_suite | 9.0 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.3 |
| mono_project | mono | 1.2.2 |
| mono_project | mono | 2.0 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.0.2.28 |
| oracle | weblogic_server_component | 9.2 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| rim | blackberry_desktop_software | * |
| ibm | lotus_notes_intellisync | * |
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.2 |
| ibm | aix | 5.2.2 |
| ibm | aix | 5.3.9 |
| ibm | aix | 5.3.7 |
| ibm | aix | 5.3.8 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.1 |
The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.13 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.1.1.18 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.19 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.1.13 |
The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2 |
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.0.0 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 5.3 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 5.3.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_partner_gateway | 6.0.0.1 |
| ibm | websphere_partner_gateway | 6.0.0.3 |
| ibm | websphere_partner_gateway | 6.0.0.6 |
| ibm | websphere_partner_gateway | 6.0.0.2 |
| ibm | websphere_partner_gateway | 6.0.0.4 |
| ibm | websphere_partner_gateway | 6.0.0.5 |
| ibm | websphere_partner_gateway | 6.0.0.7 |
| ibm | websphere_partner_gateway | 6.0.0 |
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_message_broker | * |
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | txseries | 6.2 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_process_server | 6.1.2 |
| ibm | websphere_process_server | * |
| ibm | websphere_process_server | 6.1.2.1 |
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 5.1.1.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1.0 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.3.9 |
| ibm | aix | 5.3.7 |
| ibm | aix | 5.3.8 |
| ibm | aix | 5.2.0 |
Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | catia | 5.16 |
| ibm | catia | 5.17 |
| 3ds | enovia_smarteam | * |
| ibm | catia | * |
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_hsm | 5.5.0.0 |
| ibm | tivoli_storage_manager_hsm | 5.4.2.5 |
| ibm | tivoli_storage_manager_hsm | 5.3.2.0 |
| ibm | tivoli_storage_manager_hsm | 5.4.0.0 |
| ibm | tivoli_storage_manager_hsm | 5.5.1.4 |
| ibm | tivoli_storage_manager_hsm | 5.3.5.0 |
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | 5.10.2 |
| ibm | director | 5.20.0 |
| ibm | director | 5.10.1 |
| ibm | director | * |
| ibm | director | 4.10 |
| ibm | director | 3.1.1 |
| ibm | director | 4.11 |
| ibm | director | 5.20.1 |
| ibm | director | 4.21 |
| ibm | director | 5.10.3 |
| ibm | director | 4.22 |
| ibm | director | 5.10.0 |
| ibm | director | 4.20 |
| ibm | director | 4.12 |
| ibm | director | 5.20.2 |
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director | 5.10.2 |
| ibm | director | 5.20.0 |
| ibm | director | 5.10.1 |
| ibm | director | * |
| ibm | director | 4.10 |
| ibm | director | 3.1.1 |
| ibm | director | 4.11 |
| ibm | director | 5.20.1 |
| ibm | director | 4.21 |
| ibm | director | 5.10.3 |
| ibm | director | 4.22 |
| ibm | director | 5.10.0 |
| ibm | director | 4.20 |
| ibm | director | 4.12 |
| ibm | director | 5.20.2 |
The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.0.0 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_partner_gateway | 6.1.0 |
| ibm | websphere_partner_gateway | 6.1.1 |
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | * |
| ibm | websphere_application_server | * |
| ibm | integrated_solutions_console | 6.0.1 |
Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 6.0.2.10 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.1.13 |
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 1.0 |
| ibm | websphere_application_server | 1.0.0.2 |
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | application_server | 8.2.2 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 7.0.0.0 |
| oracle | application_server | 8.3.0 |
| ibm | websphere_portal | 6.1.0.0 |
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 7.0.0.0 |
| oracle | application_server | 8.1.9 |
| ibm | websphere_portal | 6.1.0.0 |
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | application_server | 8.2.2 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 7.0.0.0 |
| oracle | application_server | 8.3.0 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | * |
The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 5.3.0 |
Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager | 8.4.1 |
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | * |
Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | network_multi-function_security | * |
| ibm | proventia_network_mail_security_system | * |
| ibm | proventia_desktop_endpoint_security | * |
| ibm | proventia_network_mail_security_system_virtual_appliance | * |
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| openafs | openafs | 1.2.11 |
| openafs | openafs | 1.5.38 |
| openafs | openafs | 1.0.3 |
| openafs | openafs | 1.2.4 |
| openafs | openafs | 1.4.0 |
| openafs | openafs | 1.4.8_pre3 |
| openafs | openafs | 1.2.3 |
| openafs | openafs | 1.5.50 |
| openafs | openafs | 1.5.58 |
| openafs | openafs | 1.5.34 |
| ibm | afs | * |
| openafs | openafs | 1.2.9 |
| openafs | openafs | 1.4.7_pre5 |
| openafs | openafs | 1.2.7 |
| openafs | openafs | 1.2.10 |
| openafs | openafs | 1.2.1 |
| openafs | openafs | 1.4.7 |
| openafs | openafs | 1.5.31 |
| openafs | openafs | 1.2.13 |
| openafs | openafs | 1.2.2a |
| openafs | openafs | 1.2.5 |
| openafs | openafs | 1.3.77 |
| openafs | openafs | 1.4.8 |
| openafs | openafs | 1.4.3 |
| openafs | openafs | 1.1.1a |
| openafs | openafs | 1.0.4 |
| openafs | openafs | 1.5.35 |
| openafs | openafs | 1.0.1 |
| openafs | openafs | 1.5.16 |
| openafs | openafs | 1.4.8_pre1 |
| openafs | openafs | 1.3.74 |
| openafs | openafs | 1.1 |
| openafs | openafs | 1.3 |
| openafs | openafs | 1.5.39 |
| openafs | openafs | 1.3.5 |
| openafs | openafs | 1.4.7_pre2 |
| openafs | openafs | 1.3.81 |
| openafs | openafs | 1.1.0 |
| openafs | openafs | 1.3.1 |
| openafs | openafs | 1.5.52 |
| openafs | openafs | 1.2 |
| openafs | openafs | 1.5.27 |
| openafs | openafs | 1.5.36 |
| openafs | openafs | 1.3.70 |
| openafs | openafs | 1.2.2 |
| openafs | openafs | 1.3.2 |
| openafs | openafs | 1.4.8_pre2 |
| openafs | openafs | 1.4.7_pre4 |
| openafs | openafs | 1.5.17 |
| openafs | openafs | 1.5.26 |
| openafs | openafs | 1.4.5 |
| openafs | openafs | 1.1.1 |
| ibm | afs | 3.6 |
| openafs | openafs | 1.0 |
| openafs | openafs | 1.4.6 |
| openafs | openafs | 1.5.33 |
| openafs | openafs | 1.5.32 |
| openafs | openafs | 1.5.57 |
| openafs | openafs | 1.0.4a |
| openafs | openafs | 1.2.8 |
| openafs | openafs | 1.5.54 |
| openafs | openafs | 1.5.55 |
| openafs | openafs | 1.4.7_pre3 |
| openafs | openafs | 1.2.6 |
| openafs | openafs | 1.5.56 |
| openafs | openafs | 1.5.30 |
| openafs | openafs | 1.0.2 |
| openafs | openafs | 1.4.7_pre1 |
| openafs | openafs | 1.4 |
| openafs | openafs | 1.4.4 |
| openafs | openafs | 1.5.53 |
| openafs | openafs | 1.2.2b |
| openafs | openafs | 1.5 |
The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_domino | 8.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bladecenter | hs12 |
| ibm | bladecenter | js12 |
| ibm | bladecenter | s |
| ibm | bladecenter | h |
| ibm | bladecenter | js22 |
| ibm | bladecenter | ls20 |
| ibm | bladecenter | hs21_xm |
| ibm | bladecenter | ls21 |
| ibm | bladecenter | hc10 |
| ibm | bladecenter | qs21 |
| ibm | bladecenter | hs21 |
| ibm | bladecenter | qs22 |
| ibm | advanced_management_module | 1.36h |
| ibm | bladecenter | e |
| ibm | bladecenter | ht |
| ibm | bladecenter | t |
| ibm | bladecenter | ls41 |
| ibm | bladecenter | hs20 |
| ibm | bladecenter | js21 |
private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bladecenter | hs12 |
| ibm | bladecenter | js12 |
| ibm | bladecenter | s |
| ibm | bladecenter | h |
| ibm | bladecenter | js22 |
| ibm | bladecenter | ls20 |
| ibm | bladecenter | hs21_xm |
| ibm | bladecenter | ls21 |
| ibm | bladecenter | hc10 |
| ibm | bladecenter | qs21 |
| ibm | bladecenter | hs21 |
| ibm | bladecenter | qs22 |
| ibm | advanced_management_module | 1.36h |
| ibm | bladecenter | e |
| ibm | bladecenter | ht |
| ibm | bladecenter | t |
| ibm | bladecenter | ls41 |
| ibm | bladecenter | hs20 |
| ibm | bladecenter | js21 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.36h |
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.0.0.2 |
| ibm | rational_clearcase | 7.0.0.4 |
| ibm | rational_clearcase | 7.0.1.2 |
| ibm | rational_clearcase | 7.0.0.3 |
| ibm | rational_clearcase | 7.0.0.1 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 7.0 |
| ibm | rational_clearcase | 7.0.1.3 |
| ibm | rational_clearcase | 7.0.1.1 |
| ibm | rational_clearcase | 7.0.1 |
Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_continuous_data_protection_for_files | 3.1.4.0 |
Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | 5.4.1.1 |
| ibm | tivoli_storage_manager_client | 5.3 |
| ibm | tivoli_storage_manager_client | 5.1 |
| ibm | tivoli_storage_manager_client | 5.4 |
| ibm | tivoli_storage_manager_client | 5.1.8.2 |
| ibm | tivoli_storage_manager_client | 5.4.1.2 |
| ibm | tivoli_storage_manager_client | 5.2.5.2 |
| ibm | tivoli_storage_manager_client | 5.3.6.4 |
| ibm | tivoli_storage_manager_express | 5.3.3.0 |
| ibm | tivoli_storage_manager_client | 5.1.8.0 |
| ibm | tivoli_storage_manager_client | 5.3.5.3 |
| ibm | tivoli_storage_manager_client | 5.2.5.3 |
| ibm | tivoli_storage_manager_client | 5.4.1.96 |
| ibm | tivoli_storage_manager_client | 5.2 |
| ibm | tivoli_storage_manager_client | 5.2.5.1 |
| ibm | tivoli_storage_manager_express | 5.3 |
| ibm | tivoli_storage_manager_client | 5.3.6.3 |
| ibm | tivoli_storage_manager_client | 5.3.5.2 |
| ibm | tivoli_storage_manager_express | 5.3.6.4 |
Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | 5.2.3 |
| ibm | tivoli_storage_manager_client | 5.3.3 |
| ibm | tivoli_storage_manager_client | 5.4.2 |
| ibm | tivoli_storage_manager_client | 5.5.0 |
| ibm | tivoli_storage_manager_client | 5.2.2 |
| ibm | tivoli_storage_manager_client | 5.3.0 |
| ibm | tivoli_storage_manager_client | 5.3.5 |
| ibm | tivoli_storage_manager_client | 5.2.4 |
| ibm | tivoli_storage_manager_client | 5.4.0 |
| ibm | tivoli_storage_manager_client | 5.3.4 |
| ibm | tivoli_storage_manager_client | 5.2.5 |
| ibm | tivoli_storage_manager_client | 5.3.2 |
| ibm | tivoli_storage_manager_client | 5.5.1 |
| ibm | tivoli_storage_manager_client | 5.2.0 |
| ibm | tivoli_storage_manager_client | 5.3.6 |
| ibm | tivoli_storage_manager_express | 5.3 |
| ibm | tivoli_storage_manager_client | 5.4.1 |
The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_client | 5.5.0.91 |
| ibm | tivoli_storage_manager_client | 5.5.1.17 |
| ibm | tivoli_storage_manager_client | 5.5.1 |
| ibm | tivoli_storage_manager_client | 5.5.0.0 |
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 7.3.4.0 |
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | * |
The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5 |
| ibm | filenet_content_manager | 4.0 |
| ibm | filenet_content_manager | 4.0.1 |
Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | jdk | 6 |
| ibm | os/400 | v5r4m0 |
| ibm | os/400 | v6r1m0 |
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 7.0.0.4 |
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 7.0.0.4 |
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 7.0.0.4 |
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 7.0.0.4 |
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_partner_gateway | 6.1.0 |
| ibm | websphere_partner_gateway | 6.1.1 |
| ibm | websphere_partner_gateway | 6.0.0 |
| ibm | websphere_partner_gateway | 6.2 |
Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.5 |
Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearquest | 7.0.0.1 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.2 |
| ibm | rational_clearquest | 7.0.0.2 |
The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_identity_manager | 5.0 |
Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_instant_messaging_and_web_conferencing | 6.5.1 |
Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass detection of malware via a modified (1) ZIP or (2) CAB archive, a related issue to CVE-2009-1240.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system | * |
| ibm | proventia_network_multi-function_security | * |
| ibm | proventia_desktop_endpoint_security | * |
| ibm | proventia_network_mail_security_system_vitual_appliance | * |
Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_identity_manager | 5.0.0.6 |
Unspecified vulnerability in IBM Tivoli Key Lifecycle Manager (TKLM) 1.0 has unknown impact and attack vectors, related to a "password security vulnerability."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tklm | 1.0 |
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.10 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.0 |
| ibm | aix | 5.2 |
| ibm | aix | 5.3.8 |
| ibm | aix | 5.2.0 |
| ibm | aix | 5.3.0 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.2.0.54 |
| ibm | aix | 5.2.2 |
| ibm | aix | 5.2.0.50 |
| ibm | aix | 5.3.9 |
| ibm | aix | 5.3.7 |
Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_business_events | 6.2 |
| ibm | websphere_business_events | 6.1 |
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.11 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.4 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.4 |
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | communications_enabled_applications | * |
IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration properties, which allows remote authenticated users to obtain unspecified data access via a property query.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.10.xc1de |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 10.0.xc4 |
| ibm | informix_dynamic_server | 10.0.tc1 |
| ibm | informix_dynamic_server | 10.0.xc3e |
| ibm | informix_dynamic_server | 10.0.xc8e |
| ibm | informix_dynamic_server | 11.1 |
| ibm | informix_dynamic_server | 10.0.xc6 |
| ibm | informix_dynamic_server | 10.0.xc8 |
| ibm | informix_dynamic_server | 10.0.xc7e |
| ibm | informix_dynamic_server | 10.0.xc5 |
| ibm | informix_dynamic_server | 10.0.xc4e |
| ibm | informix_dynamic_server | 11.10.xc1 |
| ibm | informix_dynamic_server | 10.0.xc6e |
| ibm | informix_dynamic_server | 10.0.xc7 |
| ibm | informix_dynamic_server | 11.10.xc2 |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 10.0.xc5e |
| ibm | informix_dynamic_server | 10.0.xc10 |
| ibm | informix_dynamic_server | 10.0.xc10e |
| ibm | informix_dynamic_server | 10.0.xc2e |
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 10.0.xc9 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 11.10.xc2e |
| ibm | informix_dynamic_server | 11.10.xc3 |
| ibm | informix_dynamic_server | 10.0.xc9e |
| ibm | informix_dynamic_server | 11.10.xc3e |
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.10.xc1de |
| ibm | informix_dynamic_server | 10.0.xc1 |
| ibm | informix_dynamic_server | 10.0.xc4 |
| ibm | informix_dynamic_server | 10.0.tc1 |
| ibm | informix_dynamic_server | 10.0.xc3e |
| ibm | informix_dynamic_server | 10.0.xc8e |
| ibm | informix_dynamic_server | 11.1 |
| ibm | informix_dynamic_server | 10.0.xc6 |
| ibm | informix_dynamic_server | 10.0.xc8 |
| ibm | informix_dynamic_server | 10.0.xc7e |
| ibm | informix_dynamic_server | 10.0.xc5 |
| ibm | informix_dynamic_server | 10.0.xc4e |
| ibm | informix_dynamic_server | 11.10.xc1 |
| ibm | informix_dynamic_server | 10.0.xc6e |
| ibm | informix_dynamic_server | 10.0.xc7 |
| ibm | informix_dynamic_server | 11.10.xc2 |
| emc | legato_networker | * |
| ibm | informix_dynamic_server | 10.0.xc3 |
| ibm | informix_dynamic_server | 10.0.xc5e |
| ibm | informix_dynamic_server | 10.0.xc10 |
| ibm | informix_dynamic_server | 10.0.xc10e |
| ibm | informix_dynamic_server | 10.0.xc2e |
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 10.0.xc9 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 11.10.xc2e |
| ibm | informix_dynamic_server | 11.10.xc3 |
| ibm | informix_dynamic_server | 10.0.xc9e |
| ibm | informix_dynamic_server | 11.10.xc3e |
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
| ibm | db2 | * |
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
| ibm | db2 | * |
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 8.1 |
| ibm | db2 | * |
The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce_suite | * |
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| symantec | mail_security | 6.0.8 |
| symantec | mail_security | 5.0.11 |
| symantec | mail_security | 5.0.1.181 |
| symantec | data_loss_prevention_detection_servers | 9.0.1 |
| symantec | mail_security | 5.0.12 |
| symantec | brightmail_gateway | 8.0 |
| symantec | mail_security | 7.5.4.29 |
| symantec | mail_security | 5.0.0 |
| symantec | data_loss_prevention_endpoint_agents | 8.1.1 |
| symantec | mail_security | 5.0.13 |
| symantec | data_loss_prevention_detection_servers | 8.1.1 |
| symantec | mail_security | 5.0.1.182 |
| symantec | mail_security | 7.5.8 |
| symantec | data_loss_prevention_endpoint_agents | 9.0.1 |
| symantec | data_loss_prevention_detection_servers | 10.0 |
| symantec | mail_security | 7.5.3.25 |
| symantec | mail_security | 7.5.5.32 |
| symantec | mail_security | 6.0.6 |
| symantec | data_loss_prevention_endpoint_agents | 10.0 |
| symantec | im_manager_2007 | * |
| symantec | mail_security | 6.0.7 |
| symantec | mail_security | 8.0.2 |
| symantec | mail_security | 7.5.7 |
| symantec | mail_security | 8.0 |
| symantec | mail_security | 8.0.1 |
| symantec | mail_security | 5.0.1.189 |
| ibm | lotus_notes | 8.5 |
| symantec | mail_security | 7.5.6 |
Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 6.0.2 |
| symantec | mail_security | 6.0.8 |
| symantec | mail_security | 5.0.1 |
| symantec | mail_security | 5.0.11 |
| symantec | mail_security | 5.0.1.181 |
| symantec | data_loss_prevention_detection_servers | 9.0.1 |
| ibm | lotus_notes | 8.0.0 |
| symantec | mail_security | 5.0.12 |
| autonomy | keyview | * |
| ibm | lotus_notes | 7.0.2 |
| symantec | mail_security | 5.0.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| symantec | data_loss_prevention_endpoint_agents | 8.1.1 |
| symantec | data_loss_prevention_detection_servers | 8.1.1 |
| symantec | mail_security_appliance | 5.0 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 6.0.1 |
| symantec | mail_security | 6.0.7 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| symantec | mail_security | 8.0 |
| ibm | lotus_notes | 5.0.5 |
| symantec | mail_security | 5.0.1.189 |
| symantec | mail_security | 7.5.6 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 5.02 |
| symantec | mail_security | 7.5.4.29 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| symantec | brightmail_appliance | 8.0.1 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 5.0.4 |
| symantec | mail_security | 5.0.1.182 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 5.0.10 |
| symantec | data_loss_prevention_endpoint_agents | 9.0.1 |
| symantec | mail_security_appliance | 5.0.0.24 |
| symantec | mail_security | 5.0 |
| symantec | mail_security | 5.0.10 |
| symantec | mail_security | 7.5.3.25 |
| symantec | mail_security | 7.5.5.32 |
| ibm | lotus_notes | 7.0.3 |
| symantec | mail_security | 6.0.6 |
| ibm | lotus_notes | 7.0 |
| symantec | brightmail_appliance | 5.0 |
| symantec | brightmail_appliance | 8.0.0 |
| ibm | lotus_notes | 6.5.4 |
| symantec | mail_security_appliance | 5.0.0.36 |
| ibm | lotus_notes | 6.0 |
| symantec | mail_security | 5.0.1.200 |
| symantec | data_loss_prevention_detection_servers | 7.2 |
| ibm | lotus_notes | 8.5 |
A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_connector | * |
Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.0 |
Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via unknown vectors that trigger heap corruption, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0 |
IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2006-0717. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0 |
Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0 |
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 211.241 for Domino 8.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR EZEL7UURYC.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino_web_access | 8.0.1 |
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5 |
Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial of service via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.0.0.0 |
IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.0.0 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 6 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 7.0.0.0 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other impact via malformed data.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.0.1 |
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_identity_manager | 5.0.0.5 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1.0 |
Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.0.1 |
IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failure, and daemon crash) by sending a long password over a JDBC connection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.10.xc2 |
| ibm | informix_dynamic_server | 10.00.xc8 |
| ibm | informix_dynamic_server | 10.00.xc10 |
| ibm | informix_dynamic_server | 10.00.xc4 |
| ibm | informix_dynamic_server | 10.00.xc2 |
| ibm | informix_dynamic_server | 10.00.xc6 |
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 11.50.xc2 |
| ibm | informix_dynamic_server | 10.00.xc1 |
| ibm | informix_dynamic_server | 10.00.xc5 |
| ibm | informix_dynamic_server | 11.50 |
| ibm | informix_dynamic_server | 10.0 |
| ibm | informix_dynamic_server | 11.50.xc3 |
| ibm | informix_dynamic_server | 11.50.xc4 |
| ibm | informix_dynamic_server | 11.10.xc3 |
| ibm | informix_dynamic_server | 10.00.xc9 |
| ibm | informix_dynamic_server | 10.00.xc3 |
| ibm | informix_dynamic_server | 11.10.xc1 |
| ibm | informix_dynamic_server | 11.50.xc1 |
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.0 |
| ibm | db2 | 9.5 |
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.0 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.3.7 |
| ibm | aix | 5.3.8 |
nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1 |
| ibm | aix | 6.1.0 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.3.7 |
| ibm | aix | 5.3.8 |
Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | installation_manager | 1.0 |
| ibm | installation_manager | 1.2.1 |
| ibm | installation_manager | * |
| ibm | installation_manager | 1.3.0 |
| ibm | installation_manager | 1.3.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_composite_application_manager_for_wesbsphere | 6.1.0 |
Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_client_sdk | 3.0 |
| ibm | informix_connect_runtime | 3.0 |
| ibm | informix_client_sdk | 3.50 |
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3_l |
| ibm | vios | 1.5.1 |
| ibm | aix | 5.3.10 |
| ibm | aix | 6.1.0 |
| ibm | aix | 5.3.0.20 |
| ibm | vios | * |
| ibm | aix | 5 |
| ibm | vios | 1.5.2 |
| ibm | aix | 5.3.0 |
| ibm | aix | 5.3 |
| ibm | aix | 5.2_l |
| ibm | aix | 6.1.1 |
| ibm | aix | 5.2.0.54 |
| ibm | aix | 5.2.2 |
| ibm | aix | 5.3.9 |
| ibm | aix | 5.3.7 |
| ibm | aix | 5.1l |
| ibm | aix | 6.1.3 |
| ibm | aix | 5.1 |
| ibm | aix | 5.1.0.10 |
| ibm | vios | 1.5.0 |
| ibm | aix | 6.1 |
| ibm | aix | 5.2 |
| ibm | aix | 5.3.8 |
| ibm | aix | 5.3_ml03 |
| ibm | aix | 5.2.0 |
| ibm | aix | 5l |
| ibm | vios | 1.4 |
| ibm | aix | 6.1.2 |
| ibm | aix | 5.2.0.50 |
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp, or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope parameter to ReqWebHelp/basic/searchView.jsp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requisitepro | 7.1.0 |
Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.5.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.5.0.0 |
Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | runtimes_for_java_technology | * |
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3.6 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.5 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.6, 5.4 before 5.4.2, and 5.5 before 5.5.1, when the MAILPROG option is enabled, allow attackers to read, modify, or delete arbitrary files via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remote attackers to modify the operating-system configuration via packets to the godm port (6177/tcp).
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powerha | 6.1 |
| ibm | powerha | 5.4 |
| ibm | powerha | 5.4.1 |
| ibm | powerha | 5.5 |
Multiple unspecified vulnerabilities in the Advanced Management Module firmware before 2.50G for the IBM BladeCenter T 8720-2xx and 8730-2xx have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module_firmware | 1.25 |
| ibm | advanced_management_module_firmware | 1.26e |
| ibm | advanced_management_module_firmware | 1.25e |
| ibm | advanced_management_module_firmware | 1.01 |
| ibm | advanced_management_module_firmware | 1.26k |
| ibm | advanced_management_module_firmware | 1.34e |
| ibm | advanced_management_module_firmware | 1.20f |
| ibm | advanced_management_module_firmware | 2.46c |
| ibm | advanced_management_module_firmware | 1.20 |
| ibm | advanced_management_module_firmware | 1.42f |
| ibm | advanced_management_module_firmware | 1.36h |
| ibm | advanced_management_module_firmware | 1.26i |
| ibm | advanced_management_module_firmware | 1.34b |
| ibm | advanced_management_module_firmware | 1.36d |
| ibm | advanced_management_module_firmware | 1.42i |
| ibm | advanced_management_module_firmware | 1.00 |
| ibm | advanced_management_module_firmware | 1.42n |
| ibm | advanced_management_module_firmware | 2.48d |
| ibm | advanced_management_module_firmware | * |
| ibm | advanced_management_module_firmware | 1.36k |
| ibm | advanced_management_module_firmware | 1.42t |
| ibm | advanced_management_module_firmware | 2.46j |
| ibm | advanced_management_module_firmware | 2.48n |
| ibm | advanced_management_module_firmware | 2.48g |
| ibm | advanced_management_module_firmware | 2.48c |
| ibm | advanced_management_module_firmware | 1.28g |
| ibm | advanced_management_module_firmware | 2.48l |
| ibm | advanced_management_module_firmware | 1.42d |
| ibm | advanced_management_module_firmware | 1.42o |
| ibm | advanced_management_module_firmware | 1.36g |
| ibm | advanced_management_module_firmware | 1.32d |
| ibm | advanced_management_module_firmware | 1.25i |
| ibm | advanced_management_module_firmware | 1.26b |
| ibm | advanced_management_module_firmware | 1.26h |
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_application_developer_for_websphere | 7.0.0.7 |
| ibm | rational_application_developer_for_websphere | 7.0 |
| ibm | rational_software_architect | 7.0.0.1 |
| ibm | rational_software_architect | 7.0.0.4 |
| ibm | rational_application_developer_for_websphere | 7.0.0.3 |
| ibm | rational_software_architect | 7.0.0.6 |
| ibm | rational_application_developer_for_websphere | 7.0.0.9 |
| ibm | rational_application_developer_for_websphere | 7.0.0.2 |
| ibm | rational_application_developer_for_websphere | 7.0.0.5 |
| ibm | rational_software_architect | 7.0.0.2 |
| ibm | rational_application_developer_for_websphere | 7.0.0.4 |
| ibm | rational_software_architect | 7.0.0.5 |
| ibm | rational_application_developer_for_websphere | 7.0.0.8 |
| ibm | rational_software_architect | 7.0.0.0 |
| ibm | rational_software_architect | 7.0.0.7 |
| ibm | rational_software_architect | 7.0.0.8 |
| ibm | rational_application_developer_for_websphere | 7.0.0.1 |
| ibm | rational_software_architect | 7.0.0.3 |
| ibm | rational_application_developer_for_websphere | 7.0.0.6 |
| ibm | rational_software_architect | 7.0.0.9 |
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2_universal_database | 8 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in the Web console in IBM InfoSphere Information Server 8.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 8.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application termination) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.0.0.2 |
| ibm | rational_clearquest | 5.20 |
| ibm | rational_clearquest | 6.10 |
| ibm | rational_clearquest | 6.16 |
| ibm | rational_clearcase | 7.0.1.3 |
| ibm | rational_clearcase | 7.0.1.1 |
| ibm | rational_clearcase | * |
| ibm | rational_clearquest | 6.12 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearcase | 7.0.0.4 |
| ibm | rational_clearquest | 5.00 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 2007 |
| ibm | rational_clearquest | 6.00 |
| ibm | rational_clearcase | 7.0.0.1 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 6.14 |
| ibm | rational_clearquest | 6.15 |
| ibm | rational_clearquest | 7.0.0.1 |
| ibm | rational_clearquest | 2008 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_clearquest | 7.0.2 |
| ibm | rational_clearquest | 6.13 |
Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
| ibm | lotus_inotes | 229.051 |
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a security policy to the first document added during a session, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
| ibm | filenet_p8_application_engine | 3.5.1 |
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script or HTML via the Name field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.3-P8AE-FP003 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to .jsp pages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a document's Creator-Owner full control over an annotation object, even if the default instance security has changed, which might allow remote authenticated users to bypass intended access restrictions in opportunistic circumstances.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Audit events, which might allow remote attackers to attempt content access without detection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.5 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by deleting an item that is accessed through a connector, aka SPR RELS7LARKR.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.10 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by checking out a document that is accessed through a connector, aka SPR MMOI7PSR8J.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.11 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by accessing an entry in a calendar, aka SPR MZHA7SEBJX.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.14 services for Lotus Domino, when Domino Native Authentication is enabled, might allow remote authenticated users to cause a denial of service (daemon crash) by going offline, aka SPR MLZG7UPB9N.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the userfilter parameter to pvm_user_management.php, (3) the ping parameter to sys_tools.php in a sys_ping.php action, (4) the action parameter to pvm_cert_commaction.php, (5) the action parameter to pvm_cert_serveraction.php, (6) the action parameter to pvm_smtpstore.php, (7) the l parameter to sla/index.php, or (8) unspecified stored data; and allow remote authenticated users to inject arbitrary web script or HTML via (9) saved search filters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 2.5 |
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 1.6 |
| ibm | proventia_network_mail_security_system_virtual_appliance | * |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct denial of service attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 2.5 |
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 1.6 |
| ibm | proventia_network_mail_security_system_virtual_appliance | * |
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 1.6 |
| ibm | proventia_network_mail_security_system_virtual_appliance | * |
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_virtual_appliance_firmware | 1.6 |
| ibm | proventia_network_mail_security_system_virtual_appliance | * |
Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.201 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.131 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.201 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.131 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino_web_access | * |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_inotes | * |
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.2 |
Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_web_content_management | 6.1.0.1 |
| ibm | lotus_web_content_management | 6.1.0.2 |
| ibm | lotus_web_content_management | 6.0.1.6 |
| ibm | lotus_web_content_management | 6.0.1.4 |
| ibm | lotus_web_content_management | 6.0.1.5 |
Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 8.5.0.1 |
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | 6.1.0.5 |
| ibm | http_server | 6.1.0.21 |
| ibm | http_server | 6.0.2.39 |
| ibm | http_server | 6.1.0.9 |
| ibm | http_server | 6.0.2.27 |
| oracle | http_server | 10.1.3.5.0 |
| ibm | http_server | 6.1.0.25 |
| ibm | http_server | 6.0.2.9 |
| broadcom | vmware_ace_management_server | * |
| ibm | http_server | 6.0.2.33 |
| ibm | http_server | 6.1.0.3 |
| apache | http_server | * |
| ibm | http_server | 6.0.2.29 |
| ibm | http_server | 6.0.2.35 |
| ibm | http_server | 6.1.0.2 |
| ibm | http_server | 6.1.0.23 |
| ibm | http_server | 6.0.2.1 |
| ibm | websphere_application_server | * |
| ibm | http_server | 6.0.2.23 |
| ibm | http_server | 6.0.2.31 |
| ibm | http_server | 6.1.0.15 |
| ibm | http_server | 6.0.2.7 |
| ibm | http_server | 6.0.2.15 |
| ibm | http_server | 6.1.0.27 |
| ibm | http_server | 6.0.2.25 |
| ibm | http_server | 6.1.0.7 |
| ibm | http_server | 6.0.2.11 |
| ibm | http_server | 6.1.0.11 |
| ibm | http_server | 6.0.2.21 |
| ibm | http_server | 6.1.0.13 |
| ibm | http_server | 6.0.2 |
| ibm | http_server | 6.1 |
| ibm | http_server | 6.0.2.13 |
| ibm | http_server | 6.1.0.29 |
| ibm | http_server | 6.0.2.37 |
| ibm | http_server | 6.1.0.19 |
| ibm | http_server | 6.0.2.3 |
| ibm | http_server | 6.0.2.19 |
| ibm | http_server | 6.1.0.17 |
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.1 |
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_express | 9.0 |
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.1 |
Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.1.5 |
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.0.2 |
| ibm | lotus_web_content_management | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | lotus_workplace_web_content_management | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | lotus_workplace_web_content_management | 6.0.1.7 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 5.1.0.3 |
| ibm | lotus_web_content_management | 5.1.0.5 |
| ibm | lotus_quickr | 8.0 |
| ibm | lotus_web_content_management | 6.1.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.1.0 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.1.0.2 |
| ibm | lotus_workplace_web_content_management | 5.1.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.1.2 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | lotus_web_content_management | 6.0.1.7 |
| ibm | lotus_workplace_web_content_management | 5.1.0.3 |
| ibm | lotus_workplace_web_content_management | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | lotus_web_content_management | 6.0.1.5 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | lotus_workplace_web_content_management | 6.1.0.3 |
| ibm | lotus_web_content_management | 5.1.0.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | lotus_web_content_management | 5.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | lotus_web_content_management | 6.0.0.2 |
| ibm | lotus_workplace_web_content_management | 6.0.1.5 |
| ibm | lotus_web_content_management | 6.0.1.2 |
| ibm | lotus_workplace_web_content_management | 6.0.0.2 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | lotus_web_content_management | 6.0.0.4 |
| ibm | lotus_web_content_management | 6.0.0.3 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 6.0.0.3 |
| ibm | lotus_web_content_management | 6.0.0.1 |
| ibm | lotus_web_content_management | 6.1.0.0 |
| ibm | lotus_web_content_management | 5.1.0.1 |
| ibm | websphere_portal | 5.1.0.1 |
| ibm | lotus_web_content_management | 6.0.1.0 |
| ibm | lotus_workplace_web_content_management | 6.0.0.4 |
| ibm | websphere_portal | 5.1.0.4 |
| ibm | lotus_quickr | 8.0.0.2 |
| ibm | lotus_quickr | 8.1.1.1 |
| ibm | websphere_portal | 6.0.0.4 |
| ibm | websphere_portal | 5.1.0.2 |
| ibm | websphere_portal | 5.1.0.0 |
| ibm | lotus_workplace_web_content_management | 5.1.0.4 |
| ibm | lotus_workplace_web_content_management | 6.1.0.1 |
| ibm | lotus_workplace_web_content_management | 5.1.0.5 |
| ibm | lotus_workplace_web_content_management | 6.0.1.4 |
| ibm | lotus_quickr | 8.1.1 |
| ibm | lotus_web_content_management | 6.0.1.6 |
| ibm | lotus_web_content_management | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.0.0.3 |
| ibm | lotus_web_content_management | 6.1.0.3 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | lotus_web_content_management | 6.1.0.2 |
| ibm | lotus_quickr | 8.1 |
| ibm | lotus_web_content_management | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | lotus_workplace_web_content_management | 5.1.0.2 |
| ibm | lotus_workplace_web_content_management | 6.1.0.0 |
| ibm | lotus_web_content_management | 6.0.1.4 |
| ibm | lotus_workplace_web_content_management | 5.1.0.0 |
| ibm | lotus_web_content_management | 5.1.0.4 |
| ibm | lotus_web_content_management | 6.0.0.0 |
| ibm | lotus_web_content_management | 5.1.0.3 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | lotus_workplace_web_content_management | 6.0.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.0.0 |
| ibm | websphere_portal | 5.1.0.5 |
| ibm | lotus_workplace_web_content_management | 6.0.1.1 |
Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.0.2 |
| ibm | lotus_web_content_management | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | lotus_workplace_web_content_management | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | lotus_workplace_web_content_management | 6.0.1.7 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 5.1.0.3 |
| ibm | lotus_web_content_management | 5.1.0.5 |
| ibm | lotus_quickr | 8.0 |
| ibm | lotus_web_content_management | 6.1.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.1.0 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.1.0.2 |
| ibm | lotus_workplace_web_content_management | 5.1.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.1.2 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | lotus_web_content_management | 6.0.1.7 |
| ibm | lotus_workplace_web_content_management | 5.1.0.3 |
| ibm | lotus_workplace_web_content_management | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | lotus_web_content_management | 6.0.1.5 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | lotus_workplace_web_content_management | 6.1.0.3 |
| ibm | lotus_web_content_management | 5.1.0.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | lotus_web_content_management | 5.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | lotus_web_content_management | 6.0.0.2 |
| ibm | lotus_workplace_web_content_management | 6.0.1.5 |
| ibm | lotus_web_content_management | 6.0.1.2 |
| ibm | lotus_workplace_web_content_management | 6.0.0.2 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | lotus_web_content_management | 6.0.0.4 |
| ibm | lotus_web_content_management | 6.0.0.3 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 6.0.0.3 |
| ibm | lotus_web_content_management | 6.0.0.1 |
| ibm | lotus_web_content_management | 6.1.0.0 |
| ibm | lotus_web_content_management | 5.1.0.1 |
| ibm | websphere_portal | 5.1.0.1 |
| ibm | lotus_web_content_management | 6.0.1.0 |
| ibm | lotus_workplace_web_content_management | 6.0.0.4 |
| ibm | websphere_portal | 5.1.0.4 |
| ibm | lotus_quickr | 8.0.0.2 |
| ibm | lotus_quickr | 8.1.1.1 |
| ibm | websphere_portal | 6.0.0.4 |
| ibm | websphere_portal | 5.1.0.2 |
| ibm | websphere_portal | 5.1.0.0 |
| ibm | lotus_workplace_web_content_management | 5.1.0.4 |
| ibm | lotus_workplace_web_content_management | 6.1.0.1 |
| ibm | lotus_workplace_web_content_management | 5.1.0.5 |
| ibm | lotus_workplace_web_content_management | 6.0.1.4 |
| ibm | lotus_quickr | 8.1.1 |
| ibm | lotus_web_content_management | 6.0.1.6 |
| ibm | lotus_web_content_management | 6.0.1.3 |
| ibm | lotus_workplace_web_content_management | 6.0.0.3 |
| ibm | lotus_web_content_management | 6.1.0.3 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | lotus_web_content_management | 6.1.0.2 |
| ibm | lotus_quickr | 8.1 |
| ibm | lotus_web_content_management | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | lotus_workplace_web_content_management | 5.1.0.2 |
| ibm | lotus_workplace_web_content_management | 6.1.0.0 |
| ibm | lotus_web_content_management | 6.0.1.4 |
| ibm | lotus_workplace_web_content_management | 5.1.0.0 |
| ibm | lotus_web_content_management | 5.1.0.4 |
| ibm | lotus_web_content_management | 6.0.0.0 |
| ibm | lotus_web_content_management | 5.1.0.3 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | lotus_workplace_web_content_management | 6.0.0.1 |
| ibm | lotus_workplace_web_content_management | 6.0.0.0 |
| ibm | websphere_portal | 5.1.0.5 |
| ibm | lotus_workplace_web_content_management | 6.0.1.1 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.1 |
Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.0 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0.1 |
The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, related to the nodeagent and Deployment Manager components.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.11 |
IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 6.0.2.8 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 6.0.2.9 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.32 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.4 |
Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.261 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.201 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.131 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | 229.241 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.231 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
| ibm | lotus_inotes | 229.251 |
Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.201 |
| ibm | domino_web_access | 7.0 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.131 |
| ibm | domino_web_access | 7.0.2 |
| ibm | domino_web_access | 7.0.1 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.231 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | domino_web_access | 6.5 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | domino_web_access | 8.0 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.261 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | 229.241 |
| ibm | lotus_inotes | 229.041 |
| ibm | domino_web_access | 8.0.2 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.021 |
| ibm | domino_web_access | 7.0.3 |
| ibm | lotus_inotes | 229.251 |
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.261 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.201 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.131 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | 229.241 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.231 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
| ibm | lotus_inotes | 229.251 |
Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 229.031 |
| ibm | lotus_inotes | 229.111 |
| ibm | lotus_inotes | 229.261 |
| ibm | lotus_inotes | 229.101 |
| ibm | lotus_inotes | 229.171 |
| ibm | lotus_inotes | 229.201 |
| ibm | lotus_inotes | 229.191 |
| ibm | lotus_inotes | 229.221 |
| ibm | lotus_inotes | 229.131 |
| ibm | lotus_inotes | 229.141 |
| ibm | lotus_inotes | 229.241 |
| ibm | lotus_inotes | * |
| ibm | lotus_inotes | 229.051 |
| ibm | lotus_inotes | 229.041 |
| ibm | lotus_inotes | 229.231 |
| ibm | lotus_inotes | 229.151 |
| ibm | lotus_inotes | 229.061 |
| ibm | lotus_inotes | 229.181 |
| ibm | lotus_inotes | 229.211 |
| ibm | lotus_inotes | 229.161 |
| ibm | lotus_inotes | 229.011 |
| ibm | lotus_inotes | 229.021 |
| ibm | lotus_inotes | 229.251 |
Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors. NOTE: some of these details are obtained from third party information. NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official service pack.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0.2.3 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_domino | 7.0.2.1 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 7.0.3 |
Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enovia_smarteam | 5 |
Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 6.1.0 |
| ibm | vios | 2.1 |
Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 6.1.0 |
| ibm | vios | 2.1 |
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-134,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 4.1.5 |
| ibm | aix | * |
| ibm | aix | 4.3.3 |
| ibm | aix | 430 |
| ibm | aix | 4.1 |
| ibm | aix | 2.2.1 |
| ibm | vios | * |
| ibm | aix | 3.2.5 |
| ibm | aix | 5.2_l |
| hp | nfs/oncplus | * |
| ibm | aix | 3.2.0 |
| ibm | vios | 2.1 |
| ibm | aix | 5.2.0.54 |
| ibm | aix | 5.2.2 |
| ibm | aix | 4.1.4 |
| ibm | aix | 4.3.0 |
| ibm | aix | 4.1.1 |
| ibm | aix | 3.2.4 |
| sgi | irix | 6.5 |
| ibm | aix | 4.2.0 |
| ibm | aix | 5.1l |
| ibm | aix | 3.1 |
| ibm | aix | 5.1 |
| ibm | aix | 5.1.0.10 |
| ibm | aix | 4 |
| ibm | aix | 6.1 |
| ibm | aix | 4.2.1.12 |
| ibm | aix | 4.2.1 |
| ibm | aix | 5.2 |
| ibm | aix | 1.2.1 |
| ibm | aix | 5.2.0 |
| ibm | aix | 4.3.1 |
| ibm | aix | 1.3 |
| ibm | aix | 4.3.2 |
| ibm | aix | 4.0 |
| ibm | aix | 4.1.3 |
| ibm | vios | 1.4 |
| ibm | aix | 4.3 |
| ibm | aix | 4.1.2 |
| ibm | aix | 3.2 |
| ibm | aix | 4.2 |
| ibm | aix | 5.2.0.50 |
Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_content_manager | * |
| ibm | db2_content_manager | 8.3 |
bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3.0 |
| ibm | aix | 5.3 |
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | webi | 1.0.2 |
| ibm | webi | * |
The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | webi | 1.0.2 |
| ibm | webi | * |
Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director_agent | 6.1 |
| ibm | director_agent | 6.1.2 |
Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.01 |
| ibm | advanced_management_module | 1.25 |
| ibm | advanced_management_module | 1.32 |
| ibm | advanced_management_module | 1.42 |
| ibm | advanced_management_module | 1.00 |
| ibm | advanced_management_module | 1.36 |
| ibm | advanced_management_module | * |
| ibm | advanced_management_module | 2.48 |
| ibm | advanced_management_module | 1.28 |
| ibm | advanced_management_module | 1.34 |
| ibm | advanced_management_module | 1.20 |
| ibm | advanced_management_module | 1.26 |
| ibm | advanced_management_module | 2.46 |
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 8.5 |
Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_8_business_intelligence | * |
Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | * |
Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5 |
The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.3 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.8.0.4 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.2 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.3 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.7 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.8.03 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.7 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.2 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.2 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.8.0.2 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.1 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.5 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.8.0.2 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.4 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | * |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.8.0.1 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.1 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.1 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.6 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.8.0.1 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.8.0.2 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.8.0.1 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.4 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.1 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.7 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.8.0.0 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.8.0.0 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.8.0.0 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.8.0.3 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.9 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.5 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.8 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.2 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.8.0.3 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.2 |
| ibm | websphere_datapower_b2b_appliance_xb60 | * |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.4 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.4 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.8.0.2 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.4 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.8.0.4 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | * |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.2 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.6 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.9 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.3 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.8.0.3 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.2 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.9 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.8 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.3 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.8.0.1 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.6 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.8.0.0 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.1 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.8.0.2 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.8 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.5 |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.7.3.2 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.9 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.8.0.4 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.8.0.4 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.6 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.8.0.4 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.8 |
| ibm | websphere_datapower_xml_security_gateway_xs40 | * |
| ibm | websphere_datapower_xml_security_gateway_xs40 | 3.7.3.7 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.6 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.5 |
| ibm | websphere_datapower_xml_accelerator_xa35 | * |
| ibm | websphere_datapower_b2b_appliance_xb60 | 3.8.0.3 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.8 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.3 |
| ibm | websphere_datapower_xml_accelerator_xa35 | 3.7.3.9 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.7.3.5 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.8.0.0 |
| ibm | websphere_datapower_low_latency_appliance_xm70 | 3.8.0.1 |
| ibm | websphere_datapower_datapower_integration_appliance_xi50 | 3.7.3.7 |
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.0.2.14 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.8 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 6.1.0.6 |
| ibm | websphere_application_server | 6.1.13 |
The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | communications_server | 6.1.3 |
| ibm | communications_server | 6.3.1.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.5.0 |
| ibm | lotus_connections | 2.5.0.1 |
The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.5.0 |
| ibm | lotus_connections | 2.5.0.1 |
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.5.0 |
| ibm | lotus_connections | 2.5.0.1 |
Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 2.5.0 |
| ibm | lotus_connections | 2.5.0.1 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.1 |
mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow remote attackers to cause a denial of service (daemon fail) via an upload.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_ilog_jrules | 6.7 |
Multiple unspecified vulnerabilities in IBM Rational ClearQuest before 7.1.1.02 have unknown impact and attack vectors, as demonstrated by an AppScan report.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 5.20 |
| ibm | rational_clearquest | 6.10 |
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.0.1.6 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 6.16 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearquest | 6.12 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 5.00 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.1.8 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.7 |
| ibm | rational_clearquest | 2007 |
| ibm | rational_clearquest | * |
| ibm | rational_clearquest | 7.0.1.7 |
| ibm | rational_clearquest | 6.00 |
| ibm | rational_clearquest | 7.0.1.9 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 6.14 |
| ibm | rational_clearquest | 6.15 |
| ibm | rational_clearquest | 7.0.0.6 |
| ibm | rational_clearquest | 7.0.0.9 |
| ibm | rational_clearquest | 7.0.0.1 |
| ibm | rational_clearquest | 7.0.0.8 |
| ibm | rational_clearquest | 2008 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_clearquest | 7.0.1.5 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.0.2 |
| ibm | rational_clearquest | 6.13 |
Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | p8_content_engine | 4.5.1 |
| ibm | p8_content_search_engine | 4.5.0 |
| ibm | p8_content_engine | 4.5.1.1 |
| ibm | p8_content_search_engine | 4.5.1 |
| ibm | p8_content_engine | 4.5.1.2 |
| ibm | p8_content_search_engine | 4.5.0.2 |
| ibm | p8_content_search_engine | 4.5.0.1 |
SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters to "Commerce Organization Admin Console JavaServer pages."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 6.0.0.5 |
Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.0.0 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 6.0.2.8 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 6.0.2.10 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users to cause a denial of service (disk consumption) via vectors that trigger an FDC with an RM680004 Probe Id value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.0.1.4 |
IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and "concurrency issues."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 7.0.0.1 |
IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 7.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT parameter to private/ipmi_bladestatus.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.01 |
| ibm | advanced_management_module | 1.25 |
| ibm | advanced_management_module | 1.32 |
| ibm | advanced_management_module | 1.42 |
| ibm | advanced_management_module | 1.00 |
| ibm | advanced_management_module | 1.36 |
| ibm | advanced_management_module | * |
| ibm | advanced_management_module | 2.50 |
| ibm | advanced_management_module | 2.48 |
| ibm | advanced_management_module | 1.28 |
| ibm | advanced_management_module | 3.54 |
| ibm | advanced_management_module | 1.34 |
| ibm | advanced_management_module | 1.20 |
| ibm | advanced_management_module | 1.26 |
| ibm | advanced_management_module | 2.46 |
Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.01 |
| ibm | advanced_management_module | 1.25 |
| ibm | advanced_management_module | 1.32 |
| ibm | advanced_management_module | 1.42 |
| ibm | advanced_management_module | 1.00 |
| ibm | advanced_management_module | 1.36 |
| ibm | advanced_management_module | * |
| ibm | advanced_management_module | 2.50 |
| ibm | advanced_management_module | 2.48 |
| ibm | advanced_management_module | 1.28 |
| ibm | advanced_management_module | 1.34 |
| ibm | advanced_management_module | 1.20 |
| ibm | advanced_management_module | 1.26 |
| ibm | advanced_management_module | 2.46 |
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.01 |
| ibm | advanced_management_module | 1.25 |
| ibm | advanced_management_module | 1.32 |
| ibm | advanced_management_module | 1.42 |
| ibm | advanced_management_module | 1.00 |
| ibm | advanced_management_module | 1.36 |
| ibm | advanced_management_module | * |
| ibm | advanced_management_module | 2.50 |
| ibm | advanced_management_module | 2.48 |
| ibm | advanced_management_module | 1.28 |
| ibm | advanced_management_module | 1.34 |
| ibm | advanced_management_module | 1.20 |
| ibm | advanced_management_module | 1.26 |
| ibm | advanced_management_module | 2.46 |
solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.30.0044 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 6.30.0039 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.30.0040 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.1 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | * |
| ibm | soliddb | 06.00.1018 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 4.0.1 |
| ibm | filenet_content_manager | 4.0.0 |
| ibm | filenet_content_manager | 4.5.0 |
The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | * |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value parameter to ServiceRegistry/QueryWizardProcessStep1.do.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Unspecified vulnerability in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Unspecified vulnerability in the message-protocol implementation in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (recovery failure), and possibly trigger loss of data, via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.32 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 7.0.0.4 |
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7 |
IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 4.5.0 |
IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 4.5.0 |
IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer log file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 4.5.0 |
Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 4.5.0 |
Unspecified vulnerability in the webcontainer implementation in IBM Lotus Sametime Connect 8.5.1 before CF1 has unknown impact and attack vectors, aka SPRs LXUU87S57H and LXUU87S93W.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
| ibm | lotus_sametime | 2.5 |
| ibm | lotus_sametime | 8.0 |
| ibm | lotus_sametime | 8.5 |
| ibm | lotus_sametime | 1.5 |
| ibm | lotus_sametime | 8.0.1 |
| ibm | lotus_sametime | 8.0.2 |
| ibm | lotus_sametime | 7.5 |
| ibm | lotus_sametime | 7.0 |
| ibm | lotus_sametime | 7.5.1 |
Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 1.5 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | vios | 2.1 |
Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 8.5.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 and 4.0.2.x before 4.0.2.7-P8AE-FP007 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
| ibm | filenet_p8_application_engine | 3.5.1 |
Session fixation vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.7-P8AE-FP007 allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 4.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
Open redirect vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_application_engine | 3.5.1 |
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.7 |
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.7 |
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| vmware | springsource_spring_security | 3.0.2 |
| acegisecurity | acegi-security | 1.0.0 |
| acegisecurity | acegi-security | 1.0.3 |
| vmware | springsource_spring_security | 2.0.3 |
| ibm | websphere_application_server | 7.0 |
| vmware | springsource_spring_security | 3.0.3 |
| acegisecurity | acegi-security | 1.0.5 |
| vmware | springsource_spring_security | 3.0.1 |
| acegisecurity | acegi-security | 1.0.7 |
| acegisecurity | acegi-security | 1.0.6 |
| vmware | springsource_spring_security | 2.0.2 |
| vmware | springsource_spring_security | 2.0.1 |
| vmware | springsource_spring_security | 3.0.0 |
| acegisecurity | acegi-security | 1.0.1 |
| acegisecurity | acegi-security | 1.0.4 |
| vmware | springsource_spring_security | 2.0.4 |
| ibm | websphere_application_server | 6.1 |
| vmware | springsource_spring_security | 2.0.0 |
| acegisecurity | acegi-security | 1.0.2 |
| vmware | springsource_spring_security | 2.0.5 |
Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_universal_database | 9.5 |
| ibm | db2_universal_database | * |
The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the content and length of data copied to memory, which allows remote attackers to execute arbitrary code via a crafted packet. NOTE: this might overlap CVE-2010-3059.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1) AGI_SendToLog (aka _SendToLog) function; the (2) group, (3) workgroup, or (4) domain name field to the USER_S_AddADGroup function; the (5) user_path variable to the FXCLI_checkIndexDBLocation function; or (6) the _AGI_S_ActivateLTScriptReply (aka ActivateLTScriptReply) function. NOTE: this might overlap CVE-2010-3059.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a certain value to a memory location specified by a UDP packet field, which allows remote attackers to execute arbitrary code via multiple requests. NOTE: this might overlap CVE-2010-3058.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-700. NOTE: this might overlap CVE-2010-3058 or CVE-2010-3059.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.4.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.3.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.5.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.2 |
Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | * |
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | * |
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
| ibm | omnifind | 9.1 |
| ibm | omnifind | 9.0 |
The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
| ibm | omnifind | 9.1 |
| ibm | omnifind | 9.0 |
Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | * |
| ibm | omnifind | 8.0 |
| ibm | omnifind | 6.1 |
| ibm | omnifind | 8.4 |
esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | * |
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
| ibm | omnifind | 9.1 |
| ibm | omnifind | 9.0 |
ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
| ibm | omnifind | 9.1 |
| ibm | omnifind | 9.0 |
IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
| ibm | omnifind | 9.1 |
| ibm | omnifind | 9.0 |
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | 8.0 |
| ibm | omnifind | 9.0 |
Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute arbitrary code via a crafted EXPLAIN directive, aka idsdb00154125 and idsdb00154243.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 11.50 |
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.30.0044 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 06.30.0047 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 6.1 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.30.0039 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 6.30.0040 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 06.00.1018 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.30.0044 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 06.30.0047 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 6.1 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.30.0039 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 6.30.0040 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.30.0044 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 06.30.0047 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 6.1 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.30.0039 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 6.30.0040 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenticated users to execute arbitrary code via long DBINFO keyword arguments in a SQL statement, aka idsdb00165017, idsdb00165019, idsdb00165021, idsdb00165022, and idsdb00165023.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00.tc3tl |
| ibm | informix_dynamic_server | 11.10.xc1de |
| ibm | informix_dynamic_server | 10.00.xc4 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 10.00.xc7w1 |
| ibm | informix_dynamic_server | 10.00.xc2 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 10.00.xc6 |
| ibm | informix_dynamic_server | 10.00.xc1 |
| ibm | informix_dynamic_server | 10.00.xc9 |
| ibm | informix_dynamic_server | 7.31 |
| ibm | informix_dynamic_server | 11.10.xc1 |
| ibm | informix_dynamic_server | 11.50.xc1 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xc7 |
| ibm | informix_dynamic_server | 11.10.xc2 |
| ibm | informix_dynamic_server | 10.00.xc8 |
| ibm | informix_dynamic_server | 10.00.xc10 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 11.10.tb4tl |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 11.50.xc2 |
| ibm | informix_dynamic_server | 10.00.xc5 |
| ibm | informix_dynamic_server | 10.00 |
| ibm | informix_dynamic_server | 11.50 |
| ibm | informix_dynamic_server | 11.10.xc2e |
| ibm | informix_dynamic_server | 10.00.xc3 |
Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before 10.00.xC8, and 11.10 before 11.10.xC2 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted parameter size, aka idsdb00146931, idsdb00146930, idsdb00146929, and idsdb00138308.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 10.00.tc3tl |
| ibm | informix_dynamic_server | 11.10.xc1de |
| ibm | informix_dynamic_server | 10.00.xc4 |
| ibm | informix_dynamic_server | 9.40.uc1 |
| ibm | informix_dynamic_server | 9.40.xc5 |
| ibm | informix_dynamic_server | 10.00.xc7w1 |
| ibm | informix_dynamic_server | 10.00.xc2 |
| ibm | informix_dynamic_server | 9.40.uc3 |
| ibm | informix_dynamic_server | 10.00.xc6 |
| ibm | informix_dynamic_server | 10.00.xc1 |
| ibm | informix_dynamic_server | 10.00.xc9 |
| ibm | informix_dynamic_server | 7.31 |
| ibm | informix_dynamic_server | 11.10.xc1 |
| ibm | informix_dynamic_server | 9.40.uc2 |
| ibm | informix_dynamic_server | 9.40.xc7 |
| ibm | informix_dynamic_server | 10.00.xc8 |
| ibm | informix_dynamic_server | 10.00.xc10 |
| ibm | informix_dynamic_server | 9.40.tc5 |
| ibm | informix_dynamic_server | 11.10.tb4tl |
| ibm | informix_dynamic_server | 9.40.uc5 |
| ibm | informix_dynamic_server | 11.10 |
| ibm | informix_dynamic_server | 10.00.xc5 |
| ibm | informix_dynamic_server | 10.00 |
| ibm | informix_dynamic_server | 11.50 |
| ibm | informix_dynamic_server | 10.00.xc3 |
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_test_lab_manager | * |
Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.1.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0 |
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_os_deployment | 7.1.1.3 |
IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.63 |
| ibm | tivoli_directory_server | 6.0.0.53 |
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.64 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.33 |
Unspecified vulnerability in Web Services in IBM ENOVIA 6 has unknown impact and attack vectors, related to a system that becomes "exposed to the internet."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enovia | 6 |
Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.1.0.1 |
Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.4 |
Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | omnifind | * |
| ibm | omnifind | 8.0 |
| ibm | omnifind | 6.1 |
| ibm | omnifind | 8.4 |
| ibm | omnifind | 8.5 |
reset_diragent_keys in the Common agent in IBM Systems Director 6.2.0 has 754 permissions, which allows local users to gain privileges by leveraging system group membership.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | director_agent | 6.2.0 |
Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | * |
| ibm | lotus_notes_traveler | 8.0.1.2 |
Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enovia | 6 |
Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) by making many TCP connection attempts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTTP-AS hang) by making many connection requests that trigger "queue size delta errors," related to a "timing hole" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | * |
| ibm | lotus_mobile_connect | 6.1.1.1 |
| ibm | lotus_mobile_connect | 6.1.2 |
| ibm | lotus_mobile_connect | 6.1.1 |
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dojofoundation | dojo_toolkit | * |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.2 |
Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.0.1.6 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.1.8 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.7 |
| ibm | rational_clearquest | 7.0.1.7 |
| ibm | rational_clearquest | 7.0.1.9 |
| ibm | rational_clearquest | 7.0.1.10 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 7.0.0.6 |
| ibm | rational_clearquest | 7.0.0.9 |
| ibm | rational_clearquest | 7.0.0.1 |
| ibm | rational_clearquest | 7.0.0.8 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_clearquest | 7.0.1.5 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.1.1.2 |
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.2 |
IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 does not prevent modification of back-reference fields, which allows remote authenticated users to interfere with intended record relationships, and possibly cause a denial of service (loop) or have unspecified other impact, by (1) adding or (2) removing a back reference.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.0.1.6 |
| ibm | rational_clearquest | 7.0.0.0 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.1.8 |
| ibm | rational_clearquest | 7.0.0.2 |
| ibm | rational_clearquest | 7.0.0.7 |
| ibm | rational_clearquest | 7.0.1.7 |
| ibm | rational_clearquest | 7.0.1.9 |
| ibm | rational_clearquest | 7.0.1.10 |
| ibm | rational_clearquest | 7.0 |
| ibm | rational_clearquest | 7.0.0.6 |
| ibm | rational_clearquest | 7.0.0.9 |
| ibm | rational_clearquest | 7.0.0.1 |
| ibm | rational_clearquest | 7.0.0.8 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_clearquest | 7.0.1.5 |
| ibm | rational_clearquest | 7.0.0.3 |
| ibm | rational_clearquest | 7.1.1.2 |
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
Unspecified vulnerability in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows local users to overwrite arbitrary files via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 6.2.1 |
Unspecified vulnerability in the Space Management client in the Hierarchical Storage Management (HSM) component in IBM Tivoli Storage Manager (TSM) 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows remote attackers to execute arbitrary commands via unknown vectors, related to a "script execution vulnerability."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.1.1 |
WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 allows remote authenticated users to cause a denial of service (worker thread consumption) via shift-reload actions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.1.1 |
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.0.0.53 |
Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.0.0.63 |
| ibm | tivoli_directory_server | 6.0.0.53 |
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.0.0.64 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.0.0.33 |
The authoring tool in IBM Web Content Manager (WCM) 6.1.5, and 7.0.0.1 before CF003, allows remote authenticated users to bypass intended access restrictions on draft creation by leveraging certain resource editor privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_content_manager | 7.0.01 |
| ibm | web_content_manager | 6.1.5 |
Race condition in IBM Web Content Manager (WCM) 7.0.0.1 before CF003 allows remote authenticated users to cause a denial of service (infinite recursive query) via unspecified vectors, related to a StackOverflowError exception.
CVSS 2.0
Severity: LOW
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_content_manager | 7.0.0.1 |
Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw file. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 1.3.0.20090908.0900 |
Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the current working directory, as demonstrated by a directory that contains a .vcf, .vcs, or .ics file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5 |
Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | runtimes_for_java_technology | * |
| ibm | java | 1.4.2.13.2 |
| ibm | java | 1.4.2.13.3 |
| ibm | java | * |
| ibm | runtimes_for_java_technology | 5.0.12.3 |
| ibm | runtimes_for_java_technology | 5.0.11.0 |
| ibm | java | 1.4.2 |
| ibm | runtimes_for_java_technology | 5.0.0 |
| ibm | runtimes_for_java_technology | 6.0.8.1 |
| ibm | java | 1.4.2.13.6 |
| ibm | java | 1.4.2.13 |
| ibm | java | 1.4.2.13.7 |
| ibm | runtimes_for_java_technology | 6.0.6.0 |
| ibm | java | 1.4.2.13.1 |
| ibm | runtimes_for_java_technology | 5.0.12.2 |
| ibm | runtimes_for_java_technology | 6.0.4.0 |
| ibm | java | 1.4.2.13.5 |
| ibm | runtimes_for_java_technology | 5.0.11.2 |
| ibm | runtimes_for_java_technology | 6.0.7.0 |
| ibm | runtimes_for_java_technology | 6.0.8.0 |
| ibm | runtimes_for_java_technology | 5.0.12.1 |
| ibm | runtimes_for_java_technology | 6.0.3.0 |
| ibm | java | 1.4.2.13.4 |
| ibm | runtimes_for_java_technology | 6.0.1.0 |
| ibm | runtimes_for_java_technology | 5.0.12.0 |
| ibm | runtimes_for_java_technology | 6.0.0 |
| ibm | runtimes_for_java_technology | 6.0.5.0 |
| ibm | runtimes_for_java_technology | 5.0.11.1 |
| ibm | runtimes_for_java_technology | 6.0.2.0 |
Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 6.0.2.8 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 6.0.2.9 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.0.1 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 6.0.2.10 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_8_business_intelligence | 8.4.1 |
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.0.0.23 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1 |
| ibm | tivoli_access_manager_for_e-business | 5.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.3 |
| ibm | tivoli_access_manager_for_e-business | 6.0.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.4 |
| ibm | tivoli_access_manager_for_e-business | 5.1.0.10 |
| ibm | tivoli_access_manager_for_e-business | 6.0.0.17 |
The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.1.4 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | * |
| ibm | db2 | 9.7 |
Multiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim Fix 9, have unknown impact and attack vectors, related to "security vulnerabilities of Websphere Application Server bundled within" and "many internal defects and APARs."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_integrated_portal | 1.1.1.1 |
| ibm | tivoli_common_reporting | 1.2.0 |
IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | * |
| ibm | db2 | 9.7 |
Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 8.0.2 |
Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 6.5.4.3 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 6.5.4.2 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 5.0.10 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.8a |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.2.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.5.2 |
| ibm | lotus_domino | 8.0.2.6 |
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | 7.0.4.1 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 6.0.1.2 |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.0.4 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 7.0.4 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 6.0.1.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.5.6 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_domino | 6.0.2.2 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 6.0.2.1 |
| ibm | lotus_domino | 6.0.1.3 |
| ibm | lotus_domino | 7.0.2.3 |
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | * |
| ibm | lotus_domino | 6.5.3.1 |
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 6.5.4.1 |
| ibm | lotus_domino | 6.0.1 |
| ibm | lotus_domino | 7.0.4.2 |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 4.6.4 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0.2.5 |
| ibm | lotus_domino | 7.0.2.1 |
| ibm | lotus_domino | 5.0.11 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 4.6.3 |
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 4.6.1 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 7.0.3 |
Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 6.5.4.3 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 6.5.4.2 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 5.0.10 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.8a |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.2.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.5.2 |
| ibm | lotus_domino | 8.0.2.6 |
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | 7.0.4.1 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 6.0.1.2 |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.0.4 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 7.0.4 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 6.0.1.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.5.6 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_domino | 6.0.2.2 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 6.0.2.1 |
| ibm | lotus_domino | 6.0.1.3 |
| ibm | lotus_domino | 7.0.2.3 |
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | * |
| ibm | lotus_domino | 6.5.3.1 |
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 6.5.4.1 |
| ibm | lotus_domino | 6.0.1 |
| ibm | lotus_domino | 7.0.4.2 |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 4.6.4 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0.2.5 |
| ibm | lotus_domino | 7.0.2.1 |
| ibm | lotus_domino | 5.0.11 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 4.6.3 |
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 4.6.1 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 7.0.3 |
Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in a malformed Notes calendar (aka iCalendar or iCal) meeting request, aka SPR KLYH87LL23.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 6.5.1 |
| ibm | lotus_domino | 6.0.5 |
| ibm | lotus_domino | 6.5.4.3 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 6.5.4.2 |
| ibm | lotus_domino | 6.5.5 |
| ibm | lotus_domino | 5.0.10 |
| ibm | lotus_domino | 5.0.9 |
| ibm | lotus_domino | 5.0.8a |
| ibm | lotus_domino | 6.5.3 |
| ibm | lotus_domino | 6.5.2.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.5.2 |
| ibm | lotus_domino | 8.0.2.6 |
| ibm | lotus_domino | 5.0.2 |
| ibm | lotus_domino | 6.5.4 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 5.0.5 |
| ibm | lotus_domino | 5.0.8 |
| ibm | lotus_domino | 6.0 |
| ibm | lotus_domino | 6.0.2_cf2 |
| ibm | lotus_domino | 7.0.4.1 |
| ibm | lotus_domino | 5.0.4a |
| ibm | lotus_domino | 6.0.1.2 |
| ibm | lotus_domino | 5.0.1 |
| ibm | lotus_domino | 6.5.0 |
| ibm | lotus_domino | 6.0.4 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 7.0.4 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 6.0.1.1 |
| ibm | lotus_domino | 6.0.3 |
| ibm | lotus_domino | 6.5.6 |
| ibm | lotus_domino | 5.0 |
| ibm | lotus_domino | 6.0.2.2 |
| ibm | lotus_domino | 5.0.6 |
| ibm | lotus_domino | 5.0.7 |
| ibm | lotus_domino | 6.0.2.1 |
| ibm | lotus_domino | 6.0.1.3 |
| ibm | lotus_domino | 7.0.2.3 |
| ibm | lotus_domino | 5.0.9a |
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | * |
| ibm | lotus_domino | 6.5.3.1 |
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 6.5.4.1 |
| ibm | lotus_domino | 6.0.1 |
| ibm | lotus_domino | 7.0.4.2 |
| ibm | lotus_domino | 5.0.3 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 5.0.7a |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 4.6.4 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 6.5 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0.2.5 |
| ibm | lotus_domino | 7.0.2.1 |
| ibm | lotus_domino | 5.0.11 |
| ibm | lotus_domino | 6.5.2 |
| ibm | lotus_domino | 5.0.6a |
| ibm | lotus_domino | 4.6.3 |
| ibm | lotus_domino | 6.0.2 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 4.6.1 |
| ibm | lotus_domino | 5.0.4 |
| ibm | lotus_domino | 7.0.3 |
Stack-based buffer overflow in the SMTP service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long arguments in a filename parameter in a malformed MIME e-mail message, aka SPR KLYH889M8H.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SPR KLYH87LMVX.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
Stack-based buffer overflow in the NRouter (aka Router) service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long filenames associated with Content-ID and ATTACH:CID headers in attachments in malformed calendar-request e-mail messages, aka SPR KLYH87LKRE.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
Multiple stack-based buffer overflows in the (1) POP3 and (2) IMAP services in IBM Lotus Domino allow remote attackers to execute arbitrary code via non-printable characters in an envelope sender address, aka SPR KLYH87LLVJ.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors, aka SPR PRAD89WGRS.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Confirm New Page scene."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 3.0 |
IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | 3.0 |
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.50 |
Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_build_forge | 7.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the messageString parameter in a WebMessage action or (2) the PATH_INFO.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.0.1 |
Unspecified vulnerability in the Rendition Engine (aka P8RE) 4.0.1 through 4.5.1 in IBM FileNet P8 Content Manager (CM) allows remote attackers to gain privileges via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_rendition_engine | 4.5.0 |
| ibm | filenet_p8_rendition_engine | 4.0.1 |
| ibm | filenet_p8_rendition_engine | 4.5.1 |
| ibm | filenet_p8_content_manager | * |
IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_content_engine | 4.5.1.5 |
| ibm | filenet_p8_content_engine | 4.5.1.3 |
| ibm | filenet_p8_content_engine | 4.0.1 |
| ibm | filenet_p8_content_engine | 4.0.1.13 |
| ibm | filenet_p8_content_engine | 4.5.1.6 |
| ibm | filenet_p8_content_engine | 5.0.0 |
| ibm | filenet_p8_content_engine | 4.0.1.11 |
| ibm | filenet_p8_content_engine | 4.0.1.10 |
| ibm | filenet_p8_content_engine | 4.5.0 |
| ibm | filenet_p8_business_process_manager | * |
| ibm | filenet_p8_content_engine | 4.5.1.4 |
| ibm | filenet_p8_content_manager | * |
| ibm | filenet_p8_content_engine | 4.5.0.2 |
| ibm | filenet_p8_content_engine | 4.0.1.12 |
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | * |
| ibm | lotus_sametime | 8.0 |
| ibm | lotus_sametime | 8.0.1 |
Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.0.0.4 |
| ibm | rational_clearcase | 7.0.0.7 |
| ibm | rational_common_licensing | 7.1 |
| ibm | rational_clearquest | 7.0.1.6 |
| ibm | rational_clearquest | 7.0.1.4 |
| ibm | rational_clearcase | 7.0.0.9 |
| ibm | rational_common_licensing | 7.0.0.2 |
| ibm | rational_clearcase | 7.0.1.1 |
| ibm | rational_clearcase | 7.0.1 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearcase | 7.0.1.10 |
| ibm | rational_common_licensing | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearcase | 7.0.0.6 |
| ibm | rational_clearquest | 7.1 |
| ibm | rational_common_licensing | 7.0.0.1 |
| ibm | rational_common_licensing | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_common_licensing | 7.1.1 |
| ibm | rational_clearcase | 7.0.1.7 |
| ibm | rational_clearquest | 7.0.1.10 |
| ibm | rational_clearcase | 7.0.0.5 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearcase | 7.0.1.4 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearquest | 7.0.0.8 |
| ibm | rational_clearquest | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.0.1.9 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.0.0.8 |
| ibm | rational_common_licensing | 7.0.1 |
| ibm | rational_clearquest | 7.0.0.5 |
| ibm | rational_clearquest | 7.1.0.2 |
| ibm | rational_common_licensing | 7.1.1.4 |
| ibm | rational_clearcase | 7.0.1.6 |
| ibm | rational_clearcase | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_common_licensing | 7.0.1.1 |
| ibm | rational_clearcase | 7.0.0.4 |
| ibm | rational_common_licensing | 7.1.0.1 |
| ibm | rational_clearquest | 7.0.1.11 |
| ibm | rational_clearquest | 7.0.1 |
| ibm | rational_clearquest | 7.0.1.8 |
| ibm | rational_common_licensing | 7.0 |
| ibm | rational_clearquest | 7.0.0.7 |
| ibm | rational_clearquest | 7.0.1.7 |
| ibm | rational_clearquest | 7.0.1.9 |
| ibm | rational_clearcase | 7.0.1.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearquest | 7.0.0.6 |
| ibm | rational_clearcase | 7.0.1.8 |
| ibm | rational_clearquest | 7.0.0.9 |
| ibm | rational_clearquest | 7.0.1.3 |
| ibm | rational_clearquest | 7.0.1.2 |
| ibm | rational_clearquest | 7.0.1.0 |
| ibm | rational_common_licensing | 7.0.3.1 |
| ibm | rational_clearquest | 7.0.1.5 |
| ibm | rational_clearcase | 7.0.1.2 |
| ibm | rational_common_licensing | 7.1.1.1 |
| ibm | rational_clearcase | 7.0.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_common_licensing | 7.1.1.3 |
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.2.0.8 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.2.0.15 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.2.0.13 |
| ibm | tivoli_directory_server | 6.2.0.6 |
| ibm | tivoli_directory_server | 6.3.0.1 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.1.0.24 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.1.0.29 |
| ibm | tivoli_directory_server | 6.1.0.36 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | tivoli_directory_server | 6.1.0.35 |
| ibm | tivoli_directory_server | 6.2.0.1 |
| ibm | tivoli_directory_server | 6.2.0.12 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.2.0.7 |
| ibm | tivoli_directory_server | 6.0.0.64 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.1.0.30 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.0.0.65 |
| ibm | tivoli_directory_server | 6.2.0.10 |
| ibm | tivoli_directory_server | 6.2.0.5 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.1.0.23 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.2.0.11 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.28 |
| ibm | tivoli_directory_server | 6.1.0.19 |
| ibm | tivoli_directory_server | 6.1.0.34 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.1.0.20 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0.22 |
| ibm | tivoli_directory_server | 6.0.0.63 |
| ibm | tivoli_directory_server | 6.1.0.37 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.0.0.53 |
| ibm | tivoli_directory_server | 6.2.0.4 |
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.39 |
| ibm | tivoli_directory_server | 6.2.0.14 |
| ibm | tivoli_directory_server | 6.1.0.18 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.1.0.33 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.3.0.2 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.27 |
| ibm | tivoli_directory_server | 6.1.0.25 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.21 |
| ibm | tivoli_directory_server | 6.1.0.31 |
| ibm | tivoli_directory_server | 5.2.0.4 |
| ibm | tivoli_directory_server | 6.0.0.66 |
| ibm | tivoli_directory_server | 6.1.0.26 |
| ibm | tivoli_directory_server | 6.1.0.38 |
| ibm | tivoli_directory_server | 6.2.0.3 |
| ibm | tivoli_directory_server | 6.1.0.32 |
| ibm | tivoli_directory_server | 6.1.0.1 |
| ibm | tivoli_directory_server | 6.1.0.17 |
The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLayoutData method, which allows remote attackers to execute arbitrary code via a crafted Data argument, a different vulnerability than CVE-2007-3883. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_system_architect | 11.3.1.1 |
| ibm | rational_system_architect | 11.3.1.2 |
| ibm | rational_system_architect | 11.4.0.1 |
| ibm | rational_system_architect | 11.3.1 |
| ibm | rational_system_architect | 11.4 |
| ibm | rational_system_architect | * |
| ibm | rational_system_architect | 11.3.1.3 |
| ibm | rational_system_architect | 11.3 |
IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 4.5.181 |
| ibm | soliddb | 6.3.39 |
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.3.38 |
| ibm | soliddb | 4.5.179 |
| ibm | soliddb | 6.3.40 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.3.48 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 6.1.18 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | 4.5.180 |
| ibm | soliddb | 6.0.1068 |
| ibm | soliddb | 6.0.1067 |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.3.47 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.5.0.3 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 6.3.44 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.32 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.0.2 |
Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| autonomy | keyview | * |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 4.1 |
| ibm | tivoli_management_framework | 4.3.1 |
| ibm | tivoli_management_framework | 3.7.1 |
| ibm | tivoli_management_framework | 4.1.1 |
Buffer overflow in the Journal Based Backup (JBB) feature in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows and AIX allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 4.2 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
| ibm | tivoli_storage_manager | 6.2.1 |
Buffer overflow in the Alternate Data Stream (aka ADS or named stream) functionality in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 4.2 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
| ibm | tivoli_storage_manager | 6.2.1 |
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0.2.0 |
| ibm | websphere_mq | 6.0.2.7 |
| ibm | websphere_mq | 6.0.2.3 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 6.0.2.8 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 6.0.2.9 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 6.0 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 6.0.1.0 |
| ibm | websphere_mq | 6.0.1.1 |
| ibm | websphere_mq | 6.0.2.6 |
| ibm | websphere_mq | 6.0.2.10 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 6.0.2.4 |
| ibm | websphere_mq | 6.0.2.5 |
| ibm | websphere_mq | 6.0.2.1 |
| ibm | websphere_mq | 6.0.2.2 |
The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at opportunistic time instants, as demonstrated by requests associated with an ORB_Request::getACRWorkElementPtr function call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (worker thread exhaustion and UDP messaging outage) by sending many UDP messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 4.0.1 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 3.0 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 4.0.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 3.0.2 |
| ibm | websphere_application_server | 3.52 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 4.0.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 4.0.3 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 3.0.2.4 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 3.5.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 3.5.2 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 3.5.1 |
| ibm | websphere_application_server | 3.0.2.2 |
| ibm | websphere_application_server | 3.0.2.1 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 3.5 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 3.0.2.3 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 2.0 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 3.0.21 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote attackers to access the server by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via encrypted SOAP messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via "dynamic SQL parameters."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/omnibus | 7.1.0.12 |
| ibm | tivoli_netcool/omnibus | 7.1.0.0 |
| ibm | tivoli_netcool/omnibus | 7.2.0.7 |
| ibm | tivoli_netcool/omnibus | 7.2.1.7 |
| ibm | tivoli_netcool/omnibus | 7.2.1.0 |
| ibm | tivoli_netcool/omnibus | 7.2.1.5 |
| ibm | tivoli_netcool/omnibus | * |
| ibm | tivoli_netcool/omnibus | 7.3.0.1 |
| ibm | tivoli_netcool/omnibus | 7.2.1.8 |
| ibm | tivoli_netcool/omnibus | 7.2.0.9 |
| ibm | tivoli_netcool/omnibus | 7.1.0.13 |
| ibm | tivoli_netcool/omnibus | 7.2.1.6 |
| ibm | tivoli_netcool/omnibus | 7.3.0.2 |
| ibm | tivoli_netcool/omnibus | 7.3.0.0 |
| ibm | tivoli_netcool/omnibus | 7.2.0.8 |
| ibm | tivoli_netcool/omnibus | 7.1.0.11 |
| ibm | tivoli_netcool/omnibus | 7.2.1.9 |
| ibm | tivoli_netcool/omnibus | 7.2.0.0 |
| ibm | tivoli_netcool/omnibus | 7.3.0.3 |
| ibm | tivoli_netcool/omnibus | 7.2.0.10 |
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | 1.3.12.6 |
| ibm | http_server | 1.3.12.7 |
| ibm | http_server | 1.3.26.1 |
| ibm | http_server | 1.3.26.2 |
| ibm | http_server | * |
| ibm | http_server | 2.0.42.1 |
| ibm | http_server | 2.0.42.2 |
| ibm | http_server | 1.3.19.5 |
| ibm | http_server | 1.3.28 |
| ibm | http_server | 2.0.42 |
| ibm | http_server | 1.3.19 |
| ibm | http_server | 1.3.19.4 |
| ibm | http_server | 1.3.26 |
| ibm | http_server | 1.3.6.3 |
| ibm | http_server | 1.0 |
| ibm | http_server | 1.3.19.6 |
| ibm | http_server | 1.3.28.1 |
| ibm | http_server | 2.0 |
| ibm | http_server | 1.3.12.2 |
| ibm | http_server | 1.3.12 |
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary commands on an agent server via a crafted ZIP archive.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 7.7.0.2 |
| ibm | rational_appscan | 7.9.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 7.7.0 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 7.7.0.1 |
| ibm | rational_appscan | 7.8.0 |
| ibm | rational_appscan | 7.9.0.1 |
| ibm | rational_appscan | 7.9.0.2 |
| ibm | rational_appscan | 7.9.0.3 |
| ibm | rational_appscan | 7.8.0.2 |
| ibm | rational_appscan | 5.5 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 7.8.0.1 |
| ibm | rational_appscan | 8.0.0.2 |
Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote attackers to execute arbitrary commands via a crafted .scan file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 7.8.0 |
| ibm | rational_appscan | 7.9.0 |
| ibm | rational_appscan | 7.9.0.1 |
| ibm | rational_appscan | 7.9.0.2 |
| ibm | rational_appscan | 7.9.0.3 |
| ibm | rational_appscan | 7.8.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 7.8.0.1 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.0 |
The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5 |
| ibm | lotus_sametime | 8.0.1 |
| ibm | lotus_sametime | 8.0.2 |
| ibm | lotus_sametime | 8.5.1 |
| ibm | lotus_sametime | 7.5 |
| ibm | lotus_sametime | 7.0 |
| ibm | lotus_sametime | 7.5.1.2 |
| ibm | lotus_sametime | 7.5.0.1 |
| ibm | lotus_sametime | 7.5.1 |
| ibm | lotus_sametime | 8.0 |
| ibm | lotus_sametime | 7.5.1.1 |
| ibm | lotus_sametime | 8.5.2 |
Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an Unknown Error document, a different vulnerability than CVE-2011-4171.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_ilog_rule_team_server | 7.1.1 |
The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ts3200_tape_library | * |
| ibm | ts3100_tape_library_firmware | * |
| ibm | ts3100_tape_library | * |
| ibm | ts3200_tape_library_firmware | * |
Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | * |
| ibm | db2 | 9.7.0.1 |
IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.15 |
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 6.0 |
Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 6.1.0.1 |
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | invscout.rte | 2.2.0.14 |
| ibm | invscout.rte | 2.2.0.10 |
| ibm | invscout.rte | 2.2.0.17 |
| ibm | invscout.rte | 2.2.0.2 |
| ibm | invscout.rte | 2.2.0.8 |
| ibm | invscout.rte | 2.2.0.12 |
| ibm | invscout.rte | 2.2.0.11 |
| ibm | invscout.rte | * |
| ibm | invscout.rte | 2.2.0.7 |
| ibm | invscout.rte | 2.2.0.9 |
| ibm | invscout.rte | 2.2.0.13 |
| ibm | invscout.rte | 2.2.0.4 |
| ibm | invscout.rte | 2.2.0.15 |
IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.1.2.10 |
| ibm | aix | 6.1 |
| ibm | vios | 2.1.2.12 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | aix | 7.1 |
| ibm | vios | 2.1.2.13 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | aix | 5.3 |
| ibm | vios | 2.1.3.10 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.1.0.0 |
| ibm | vios | 2.2.1.0 |
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager_business_gateway | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.0 |
| ibm | rational_license_key_server | 8.1 |
| ibm | rational_license_server | 7.0 |
| ibm | telelogic_license_server | 2.0 |
| ibm | rational_license_key_server | 8.1.2 |
| ibm | rational_license_server | 7.5 |
| ibm | rational_license_server | 7.1 |
| ibm | rational_license_key_server | 8.1.1 |
SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.0.5 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | * |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.5 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 8.0.2.6 |
IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers to cause a denial of service (memory consumption) by establishing many UI sessions within one HTTP session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | trivoli_service_request_manager | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | trivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | tivoli_change_and_configuration_management_database | 6.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.1 |
Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | maximo_asset_management_essentials | 7.1 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | maximo_asset_management_essentials | 7.1 |
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | trivoli_service_request_manager | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | trivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | tivoli_change_and_configuration_management_database | 6.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.1 |
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.1 |
Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 7.0.3.1 |
| ibm | lotus_notes | 7.0.4.1 |
| ibm | lotus_notes | 8.0.0 |
| autonomy | keyview | * |
| ibm | lotus_notes | 6.5.6 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 4.6 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 7.0.4.2 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 3.0.0.2 |
| ibm | lotus_notes | 5.0.7a |
| ibm | lotus_notes | 6.0.3 |
| ibm | lotus_notes | 6.0.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 5.0.2b |
| ibm | lotus_notes | 5.0.6 |
| ibm | lotus_notes | 5.0.8 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 5.0 |
| ibm | lotus_notes | 5.0.5.01 |
| ibm | lotus_notes | 3.0.0.1 |
| ibm | lotus_notes | 6.0.4 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 5.0.12 |
| ibm | lotus_notes | 6.5.3.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 5.02 |
| ibm | lotus_notes | 5.0.6a.01 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 4.2.1 |
| ibm | lotus_notes | 5.0.7 |
| ibm | lotus_notes | 6.5.6.3 |
| ibm | lotus_notes | 6.5 |
| ibm | lotus_notes | 4.6.7a |
| ibm | lotus_notes | 5.0.4 |
| ibm | lotus_notes | 6.5.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 6.5.5.2 |
| ibm | lotus_notes | 4.2 |
| ibm | lotus_notes | 7.0.2.1 |
| ibm | lotus_notes | 5.0a |
| ibm | lotus_notes | 4.6.7h |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 5.0.5.02 |
| ibm | lotus_notes | 6.5.4 |
| ibm | lotus_notes | 6.0 |
| ibm | lotus_notes | 6.5.6.1 |
| ibm | lotus_notes | 6.5.4.2 |
| ibm | lotus_notes | 6.0.2 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 7.0.2 |
| ibm | lotus_notes | 4.2.2 |
| ibm | lotus_notes | 6.5.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 5.0.1a |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 6.5.5.3 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 5.0.3 |
| ibm | lotus_notes | 7.0.4 |
| ibm | lotus_notes | 6.5.6.2 |
| ibm | lotus_notes | 5.0.2 |
| ibm | lotus_notes | 5.0.1.02 |
| ibm | lotus_notes | 5.0.6a |
| ibm | lotus_notes | 5.0.9a |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 3.0 |
| ibm | lotus_notes | 6.5.4.1 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 6.0.1 |
| ibm | lotus_notes | 5.0.11 |
| ibm | lotus_notes | 6.5.1 |
| ibm | lotus_notes | 6.5.5 |
| ibm | lotus_notes | 7.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 5.0.5 |
| ibm | lotus_notes | 5.0.9 |
| ibm | lotus_notes | 7.0.1.1 |
| ibm | lotus_notes | 5.0.1 |
| ibm | lotus_notes | 7.0.0 |
| ibm | lotus_notes | 7.0.2.3 |
| ibm | lotus_notes | 4.5 |
| ibm | lotus_notes | * |
| ibm | lotus_notes | 5.0.10 |
| ibm | lotus_notes | 6.0.2.2 |
| ibm | lotus_notes | 6.5.4.3 |
| ibm | lotus_notes | 7.0.3 |
| ibm | lotus_notes | 7.0 |
| ibm | lotus_notes | 5.0.1b |
| ibm | lotus_notes | 6.5.5.1 |
| ibm | lotus_notes | 5.0.2a |
| ibm | lotus_notes | 7.0.2.2 |
| ibm | lotus_notes | 5.0.1c |
| ibm | lotus_notes | 5.0.2c |
| ibm | lotus_notes | 7.0.4.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 5.0.4a |
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2.3 |
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_domino | 7.0.4.2 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2 |
| ibm | lotus_domino | 8.0.2.6 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 7.0 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_domino | 7.0.4.1 |
| ibm | lotus_domino | 8.0.2.5 |
| ibm | lotus_domino | 7.0.2.1 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 7.0.4 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.3 |
| ibm | lotus_domino | 7.0.3 |
The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | * |
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1242.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | webi | 1.0.4 |
Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | webi | 1.0.4 |
solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 4.5.167 |
| ibm | soliddb | 6.3.38 |
| ibm | soliddb | 4.5.179 |
| ibm | soliddb | 6.30.0044 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.1.20 |
| ibm | soliddb | 6.1.18 |
| ibm | soliddb | 4.5.178 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 4.5.169 |
| ibm | soliddb | 6.1 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 4.5.168 |
| ibm | soliddb | 6.30.0039 |
| ibm | soliddb | 4.5.176 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 6.30.0040 |
| ibm | soliddb | 4.5.173 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 4.5.175 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 6.0.1060 |
The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 6.0.2.20 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.1.0.32 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.2.18 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 6.0.2.12 |
| ibm | websphere_application_server | 6.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.10 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.43 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 6.0.0.41 |
| ibm | tivoli_directory_server | 6.2.0.8 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 6.2.0.15 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.0.0.52 |
| ibm | tivoli_directory_server | 6.2.0.13 |
| ibm | tivoli_directory_server | 6.2.0.6 |
| ibm | tivoli_directory_server | 6.3.0.1 |
| ibm | tivoli_directory_server | 6.0.0.14 |
| ibm | tivoli_directory_server | 6.1.0.24 |
| ibm | tivoli_directory_server | 6.0.0.56 |
| ibm | tivoli_directory_server | 6.1.0.29 |
| ibm | tivoli_directory_server | 6.1.0.36 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | tivoli_directory_server | 6.1.0.35 |
| ibm | tivoli_directory_server | 6.2.0.1 |
| ibm | tivoli_directory_server | 6.2.0.12 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.0.0.60 |
| ibm | tivoli_directory_server | 6.0.0.57 |
| ibm | tivoli_directory_server | 6.2.0.7 |
| ibm | tivoli_directory_server | 6.0.0.64 |
| ibm | tivoli_directory_server | 6.0.0.1 |
| ibm | tivoli_directory_server | 6.1.0.30 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.0.0.65 |
| ibm | tivoli_directory_server | 6.2.0.10 |
| ibm | tivoli_directory_server | 6.2.0.5 |
| ibm | tivoli_directory_server | 6.0.0.33 |
| ibm | tivoli_directory_server | 6.1.0.23 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.2.0.11 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.28 |
| ibm | tivoli_directory_server | 6.1.0.19 |
| ibm | tivoli_directory_server | 6.1.0.34 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.0.0.62 |
| ibm | tivoli_directory_server | 6.1.0.20 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.0.0.55 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0.22 |
| ibm | tivoli_directory_server | 6.0.0.63 |
| ibm | tivoli_directory_server | 6.1.0.37 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.0.0.53 |
| ibm | tivoli_directory_server | 6.2.0.4 |
| ibm | tivoli_directory_server | 6.0.0.19 |
| ibm | tivoli_directory_server | 6.0.0.58 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.0.0.45 |
| ibm | tivoli_directory_server | 6.0.0.54 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.39 |
| ibm | tivoli_directory_server | 6.2.0.14 |
| ibm | tivoli_directory_server | 6.1.0.18 |
| ibm | tivoli_directory_server | 6.0.0.0 |
| ibm | tivoli_directory_server | 6.0.0.61 |
| ibm | tivoli_directory_server | 6.1.0.33 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.3.0.2 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.27 |
| ibm | tivoli_directory_server | 6.1.0.25 |
| ibm | tivoli_directory_server | 6.0.0.59 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.21 |
| ibm | tivoli_directory_server | 6.1.0.31 |
| ibm | tivoli_directory_server | 5.2.0.4 |
| ibm | tivoli_directory_server | 6.0.0.66 |
| ibm | tivoli_directory_server | 6.1.0.26 |
| ibm | tivoli_directory_server | 6.1.0.38 |
| ibm | tivoli_directory_server | 6.2.0.3 |
| ibm | tivoli_directory_server | 6.1.0.32 |
| ibm | tivoli_directory_server | 6.1.0.1 |
| ibm | tivoli_directory_server | 6.1.0.17 |
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 5.2.0.4 |
IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_build_forge | 7.1.0 |
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | * |
| ibm | db2 | 9.7 |
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | * |
| ibm | db2 | 9.7 |
SQL injection vulnerability in TMWeb in IBM Datacap Taskmaster Capture 8.0.1 before FP1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap_taskmaster_capture | 8.0.1 |
The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap_taskmaster_capture | 8.0.1 |
IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap_taskmaster_capture | 8.0.1 |
The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of service (batch abort) via a long subject line in an e-mail message that is represented in a .eml file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap_taskmaster_capture | 8.0.1 |
| ibm | datacap_taskmaster_capture | * |
Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | virtualization_manager | 1.2.2 |
| ibm | systems_director | 1.2.2 |
Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 7.0.0.1 |
The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.0.1.7 |
Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, which makes it easier for remote attackers to send requests to restricted pages via a session on TCP port 9495, a different vulnerability than CVE-2011-1220.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_management_framework | 4.1 |
| ibm | tivoli_management_framework | 4.3.1 |
| ibm | tivoli_management_framework | 3.7.1 |
| ibm | tivoli_management_framework | 4.1.1 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 3.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 3.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_web_access | 1.4.0.1 |
| ibm | rational_doors_web_access | 1.4.0.3 |
| ibm | rational_doors_web_access | 1.4.0.2 |
| ibm | rational_doors_web_access | 1.4 |
Unspecified vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 has unknown impact and remote attack vectors related to the "server error response."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_web_access | 1.4.0.1 |
| ibm | rational_doors_web_access | 1.4.0.3 |
| ibm | rational_doors_web_access | 1.4.0.2 |
| ibm | rational_doors_web_access | 1.4 |
IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_web_access | 1.4.0.1 |
| ibm | rational_doors_web_access | 1.4.0.3 |
| ibm | rational_doors_web_access | 1.4.0.2 |
| ibm | rational_doors_web_access | 1.4 |
The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_web_access | 1.4.0.1 |
| ibm | rational_doors_web_access | 1.4.0.3 |
| ibm | rational_doors_web_access | 1.4.0.2 |
| ibm | rational_doors_web_access | 1.4 |
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_content_manager | * |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.2 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.2.0.1 |
The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.2 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.2.0.1 |
Multiple unspecified vulnerabilities in IBM Lotus Symphony 3 before FP3 have unknown impact and attack vectors, related to "critical security vulnerability issues."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via the sample .doc document that incorporates a user-defined toolbar.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via a .docx document with empty bullet styles for parent bullets.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
IBM Lotus Symphony 3 before FP3 on Linux allows remote attackers to cause a denial of service (application crash) via a certain sample document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application hang) via complex graphics in a presentation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | 3.0.0 |
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_datastage | 8.5 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_datastage | 8.5.0.1 |
| ibm | infosphere_information_server | 8.5 |
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_datastage | 8.5 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_datastage | 8.5.0.1 |
| ibm | infosphere_information_server | 8.5 |
Unspecified vulnerability in the Runtime in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03048.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass intended intrusion prevention by dividing a dangerous parameter value into substrings, as demonstrated by a SQL statement that is split across multiple iid parameters and then sent to a .aspx file on an IIS web server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | gx4004_ips-gx4004-ib-2_appliance | 31.030 |
| ibm | web_application_firewall | - |
| ibm | g400_ips-g400-ib-1_appliance | 31.030 |
The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 1.4.2.13.9 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openadmin_tool | 2.21 |
| ibm | openadmin_tool | * |
| ibm | openadmin_tool | 2.27 |
| ibm | openadmin_tool | 2.26 |
| ibm | openadmin_tool | 2.22 |
| ibm | openadmin_tool | 2.24 |
| ibm | openadmin_tool | 2.28 |
| ibm | openadmin_tool | 2.20 |
| ibm | openadmin_tool | 2.23 |
| ibm | openadmin_tool | 2.25 |
IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_build_forge | 7.1.2 |
Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2 |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring_for_databases | * |
| ibm | db2 | 9.7 |
Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the project parameter to teamserver/faces/home.jsp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_ilog_rule_team_server | 7.1.1 |
The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_tools_for_z/os | 2.3.0 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_mobile_connect | 6.1.4 |
IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/reporter | 2.2.0.3 |
| ibm | tivoli_netcool/reporter | 2.2.0.4 |
| ibm | tivoli_netcool/reporter | 2.2.0 |
| ibm | tivoli_netcool/reporter | 2.2.0.7 |
| ibm | tivoli_netcool/reporter | 2.2.0.5 |
| ibm | tivoli_netcool/reporter | 2.2.0.6 |
| ibm | tivoli_netcool/reporter | 2.2.0.2 |
| ibm | tivoli_netcool/reporter | 2.2.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Rational Asset Manager before 7.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_asset_manager | 7.1.1.1 |
| ibm | rational_asset_manager | 7.5.0.1 |
| ibm | rational_asset_manager | * |
| ibm | rational_asset_manager | 7.0.0.1 |
| ibm | rational_asset_manager | 7.1.1.0 |
| ibm | rational_asset_manager | 7.2.0.2 |
| ibm | rational_asset_manager | 7.5.0.0 |
| ibm | rational_asset_manager | 7.1.0.1 |
| ibm | rational_asset_manager | 7.2.0.1 |
| ibm | rational_asset_manager | 7.0.0.2 |
| ibm | rational_asset_manager | 7.1.0.0 |
| ibm | rational_asset_manager | 7.0.0.0 |
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | trivoli_service_request_manager | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | trivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | tivoli_change_and_configuration_management_database | 6.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.1 |
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | trivoli_service_request_manager | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | trivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | tivoli_change_and_configuration_management_database | 6.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.1 |
Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | maximo_asset_management_essentials | 7.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | maximo_asset_management_essentials | 7.1 |
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a ROWNUM condition involving a subquery.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.5.0.4 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.5 |
| ibm | soliddb | 6.5.0.7 |
| ibm | soliddb | 6.5.0.6 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.5.0.3 |
| ibm | soliddb | 7.0.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_experience_factory | 7.0.1 |
| ibm | web_experience_factory | 7.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_expeditor | 6.2.3 |
| ibm | lotus_expeditor | 6.2.2 |
| ibm | lotus_expeditor | 6.1.1 |
| ibm | lotus_expeditor | 6.2 |
| ibm | lotus_expeditor | 6.1 |
| ibm | lotus_expeditor | 6.2.1 |
Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_expeditor | 6.2.3 |
| ibm | lotus_expeditor | 6.2.2 |
| ibm | lotus_expeditor | 6.1.1 |
| ibm | lotus_expeditor | 6.2 |
| ibm | lotus_expeditor | 6.1 |
| ibm | lotus_expeditor | 6.2.1 |
Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_data_collection | 6.0 |
| ibm | spss_data_collection | 6.0.1 |
| ibm | spss_data_collection | 5.6 |
| ibm | spss_dimensions | 5.5 |
Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVIEW6.ocx in IBM SPSS SamplePower 3.0 allow remote attackers to execute arbitrary code via a crafted HTML document.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0 |
Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_data_collection | 6.0 |
| ibm | spss_data_collection | 6.0.1 |
| ibm | spss_data_collection | 5.6 |
| ibm | spss_dimensions | 5.5 |
The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_expeditor | 6.2.3 |
| ibm | lotus_expeditor | 6.2.2 |
| ibm | lotus_expeditor | 6.1.1 |
| ibm | lotus_expeditor | 6.2 |
| ibm | lotus_expeditor | 6.1 |
| ibm | lotus_expeditor | 6.2.1 |
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_symphony | 3.0.0.2 |
| ibm | lotus_symphony | 3.0.0.1 |
| ibm | lotus_symphony | * |
| ibm | lotus_symphony | 1.3 |
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.2.0 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.0.0.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.43 |
| ibm | websphere_application_server | 6.0.2.21 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.2.8 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.0.1.0 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.1.12 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via the display name.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | trivoli_service_request_manager | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | trivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | tivoli_change_and_configuration_management_database | 6.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management_essentials | 6.2 |
| ibm | tivoli_change_and_configuration_management_database | 7.1 |
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_express_for_software_distribution | 4.1.1 |
Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the register.do servlet, (3) the User.isExistingUser function in the logon.do servlet, (4) the Asset.getHWKey function in the CallHomeExec servlet, (5) the Asset.getMimeType function in the getAttachment (aka GetAttachmentServlet) servlet, (6) the addAsset.do servlet, or (7) a crafted EG2 file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_provisioning_manager_express_for_software_distribution | 4.1.1 |
The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a redundant WHERE condition.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.5.0.4 |
| ibm | soliddb | * |
| ibm | soliddb | 6.5.0.5 |
| ibm | soliddb | 6.5.0.7 |
| ibm | soliddb | 6.5.0.6 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.5.0.3 |
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | personal_communications | 5.9.7.0 |
| ibm | personal_communications | 5.9.7.1 |
| ibm | personal_communications | 6.0.3.0 |
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 9.4.1.3 |
| ibm | cognos_tm1 | 9.5.2 |
| ibm | cognos_tm1 | 9.4.1 |
| ibm | cognos_tm1 | 9.5.1 |
Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_metadata_workbench | 8.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_metadata_workbench | 8.5 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_metadata_workbench | 8.7 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_metadata_workbench | 8.1.2 |
| ibm | infosphere_metadata_workbench | 8.1.1 |
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_import_export_manager | 8.5 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_import_export_manager | 8.1.1 |
| ibm | infosphere_import_export_manager | 8.1.2 |
| ibm | infosphere_import_export_manager | 9.1 |
| ibm | infosphere_import_export_manager | 8.1 |
| ibm | infosphere_information_server_metabrokers_&_bridges | - |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_import_export_manager | 8.7 |
| ibm | infosphere_information_server | 8.7 |
InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_metadata_workbench | 8.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_metadata_workbench | 8.5 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_metadata_workbench | 8.7 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_metadata_workbench | 8.1.2 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_metadata_workbench | 8.1.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 9.4.0 |
| ibm | cognos_executive_viewer | * |
| ibm | cognos_tm1 | * |
| ibm | cognos_tm1 | 9.4.1 |
The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_fasttrack | 8.5 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_fasttrack | 8.7 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_fasttrack | 8.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_fasttrack | 8.1.1 |
| ibm | infosphere_fasttrack | 8.1.2 |
The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_datastage | - |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 8.7 |
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server_information_services_framework | - |
Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server_information_services_framework | - |
InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server_metabrokers_&_bridges | - |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
IBM Scale Out Network Attached Storage (SONAS) 1.3 before 1.3.2.3 requires cleartext storage of LDAP credentials without recommending a less privileged LDAP account, which might allow attackers to obtain sensitive server information by leveraging root access to a client machine.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | scale_out_network_attached_storage | 1.3 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.2 |
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 7.1.1 |
| ibm | rational_clearquest | 8.0.0 |
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7 |
The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7 |
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.0.0 |
| ibm | smartcloud_control_desk | 7.0 |
Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_change_and_configuration_management_database | 7.2.1 |
| ibm | ilog_jviews_gantt | - |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 7.0.0.13 |
IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 7.0.0.13 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 8.2 |
| ibm | tivoli_endpoint_manager | 8.0 |
| ibm | tivoli_endpoint_manager | 8.1 |
Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 7.0.0.13 |
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.1.0.45 |
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 4.1 |
| ibm | tivoli_directory_server | 6.2.0 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.22 |
| ibm | tivoli_directory_server | * |
| ibm | tivoli_directory_server | 6.1.0.48 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.0.0 |
| ibm | tivoli_directory_server | 6.1.0.47 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 3.2.2 |
| ibm | tivoli_directory_server | 6.1.0.46 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.0.0.69 |
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | smartcloud_control_desk | 7.0 |
Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan | 5.6.0 |
| ibm | rational_appscan | 5.5.0 |
| ibm | rational_appscan | 8.0.1.1 |
| ibm | rational_appscan | 5.5.0.2 |
| ibm | rational_appscan | 8.0.0.1 |
| ibm | rational_appscan | 8.0.0.3 |
| ibm | rational_appscan | 5.6.0.3 |
| ibm | rational_appscan | 8.0.0 |
| ibm | rational_appscan | 5.4 |
| ibm | rational_appscan | 5.2 |
| ibm | rational_appscan | 8.5.0 |
| ibm | rational_appscan | 5.5.0.1 |
| ibm | rational_appscan | 8.0.1 |
| ibm | rational_appscan | 8.5.0.0 |
| ibm | rational_appscan | 8.0.0.2 |
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 6.0.0.0 |
| ibm | security_appscan | 6.0.2.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 6.1.1.0 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | security_appscan | 6.0.1.0 |
| ibm | rational_policy_tester | 5.5.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 5.5.0.2 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.5.0.0 |
| ibm | rational_policy_tester | 5.6.0.2 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | * |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | * |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | rational_policy_tester | 5.6.0.3 |
| ibm | rational_policy_tester | 5.6.0.1 |
Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.2 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | tivoli_directory_server | 6.3.0.9 |
| ibm | tivoli_directory_server | 6.3.0.10 |
| ibm | tivoli_directory_server | 6.3.0 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.3.0.8 |
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 6.0.0.0 |
| ibm | security_appscan | 6.0.2.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 6.1.1.0 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | security_appscan | 6.0.1.0 |
| ibm | rational_policy_tester | 5.5.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 5.5.0.2 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.5.0.0 |
| ibm | rational_policy_tester | 5.6.0.2 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | * |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | * |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | rational_policy_tester | 5.6.0.3 |
| ibm | rational_policy_tester | 5.6.0.1 |
IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_event_pump | 4.2.2 |
IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.1.0.45 |
| ibm | tivoli_directory_server | 5.2.0 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | tivoli_directory_server | 6.0.0.7 |
| ibm | tivoli_directory_server | 4.1 |
| ibm | tivoli_directory_server | 6.2.0 |
| ibm | tivoli_directory_server | 6.0.0.8 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.22 |
| ibm | tivoli_directory_server | * |
| ibm | tivoli_directory_server | 6.1.0.48 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.0.0 |
| ibm | tivoli_directory_server | 6.1.0.47 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 3.2.2 |
| ibm | tivoli_directory_server | 6.1.0.46 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.0.0.69 |
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.1.2.12 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | aix | 7.1 |
| ibm | vios | 2.1.2.13 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | aix | 5.3 |
| ibm | vios | 2.1.3.10 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.1.0.10 |
| ibm | vios | 2.2.1.0 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.0.0 |
| ibm | smartcloud_control_desk | 7.0 |
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 4.0 |
Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 9.5.2 |
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5 |
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 8.0 |
| ibm | tivoli_endpoint_manager | * |
The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500_firmware | i3.1 |
| quantum | scalar_i500_firmware | i7 |
| quantum | scalar_i500_firmware | i3 |
| quantum | scalar_i500_firmware | i2 |
| quantum | scalar_i500_firmware | * |
| quantum | scalar_i500_firmware | i7.0.1 |
| dell | powervault_ml6000 | 41u |
| dell | powervault_ml6000 | 32u |
| dell | powervault_ml6030 | 23u |
| quantum | scalar_i500_firmware | sp4 |
| quantum | scalar_i500_firmware | i4 |
| ibm | ts3310_tape_library_firmware | * |
| quantum | scalar_i500_firmware | i5.1 |
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6020 | 14u |
| ibm | ts3310_tape_library | 3573 |
| quantum | scalar_i500_firmware | i5 |
| quantum | scalar_i500_firmware | i6 |
| quantum | scalar_i500_firmware | sp4.2 |
| quantum | scalar_i500 | 23u |
| ibm | ts3310_tape_library | 3576 |
| quantum | scalar_i500 | 14u |
| quantum | scalar_i500_firmware | i6.1 |
| dell | powervault_ml6000_firmware | 585g.gs003 |
| dell | powervault_ml6010 | 5u |
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_data_collection | 6.0 |
| ibm | spss_data_collection | 6.0.1 |
| ibm | security_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 7.0 |
| ibm | security_appscan_source | 8.0 |
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_data_collection | 6.0 |
| ibm | spss_data_collection | 6.0.1 |
| ibm | security_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 7.0 |
| ibm | security_appscan_source | 8.0 |
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 5.0.2.6 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 5.1.1.12 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 5.1.0.2 |
| ibm | websphere_application_server | 5.1.1.16 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 5.1.1.9 |
| ibm | websphere_application_server | 5.0.2.2 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 5.1.1.8 |
| ibm | websphere_application_server | 5.1.1 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 5.0.2.4 |
| ibm | websphere_application_server | 5.0.2.15 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 5.0.2.10 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 5.1.1.11 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 5.0.2.7 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 5.0.2.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 5.1.1.3 |
| ibm | websphere_application_server | 5.1.0.3 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 5.0.2.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 5.1.1.17 |
| ibm | websphere_application_server | 5.0.2.13 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 5.1.1.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 5.1.1.15 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 5.1.1.10 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 5.0.2.14 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 5.0.2.16 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 5.0.2.12 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 5.1.1.5 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 5.0.0 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 5.0.2.8 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 5.0.2 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 5.1.0.4 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 5.1.1.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 5.0.1 |
| ibm | websphere_application_server | 5.1.1.6 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 5.0.2.11 |
| ibm | websphere_application_server | 5.0.2.1 |
| ibm | websphere_application_server | 5.0.2.5 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 5.1.1.7 |
| ibm | websphere_application_server | 5.1.1.1 |
| ibm | websphere_application_server | 5.1.1.13 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 5.1.0.5 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 5.1.1.4 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via the (1) Command Line Interface or (2) Graphical User Interface, related to a "code injection" issue.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | scale_out_network_attached_storage | 1.3.1 |
| ibm | scale_out_network_attached_storage | 1.1 |
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0 |
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | xiv_storage_system_2812-a14_firmware | * |
| ibm | xiv_storage_system_2810-114_firmware | * |
| ibm | xiv_storage_system_2810-a14_firmware | * |
| ibm | xiv_storage_system_2812-114_firmware | * |
The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | xiv_storage_system_gen3 | 2810 |
| ibm | xiv_storage_system_gen3_firmware | * |
| ibm | xiv_storage_system_gen3 | 2812-114 |
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0 |
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 7.0.0.13 |
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_storage_ds3524 | 1746 |
| ibm | system_storage_ds3512 | 1746 |
| ibm | ds_storage_manager_host_software | 10.60.x5.14 |
| ibm | system_storage_ds3400 | 1726 |
| ibm | ds4700 | 1814 |
| ibm | system_storage_dcs3700_storage_subsystem | 1818 |
| ibm | system_storage_ds5300_storage_controller | 1818 |
| ibm | ds4100 | * |
| ibm | system_storage_ds3300 | 1726 |
| ibm | ds4100 | 1724 |
| ibm | system_storage_ds3950_express | 1814 |
| ibm | ds4300 | 1722 |
| ibm | ds4800 | 1815 |
| ibm | system_storage_ds5020_disk_controller | 1814-20a |
| ibm | ds_storage_manager_host_software | * |
| ibm | ds_storage_manager_host_software | 10.8 |
| ibm | system_storage_ds3200 | 1726 |
| ibm | system_storage_ds5100_storage_controller | 1818 |
| ibm | ds4400 | 1742 |
| ibm | ds4500 | 1742 |
| ibm | ds4200 | 1814 |
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_storage_ds3524 | 1746 |
| ibm | system_storage_ds3512 | 1746 |
| ibm | ds_storage_manager_host_software | 10.60.x5.14 |
| ibm | system_storage_ds3400 | 1726 |
| ibm | ds4700 | 1814 |
| ibm | system_storage_dcs3700_storage_subsystem | 1818 |
| ibm | system_storage_ds5300_storage_controller | 1818 |
| ibm | ds4100 | * |
| ibm | system_storage_ds3300 | 1726 |
| ibm | ds4100 | 1724 |
| ibm | system_storage_ds3950_express | 1814 |
| ibm | ds4300 | 1722 |
| ibm | ds4800 | 1815 |
| ibm | system_storage_ds5020_disk_controller | 1814-20a |
| ibm | ds_storage_manager_host_software | * |
| ibm | ds_storage_manager_host_software | 10.8 |
| ibm | system_storage_ds3200 | 1726 |
| ibm | system_storage_ds5100_storage_controller | 1818 |
| ibm | ds4400 | 1742 |
| ibm | ds4500 | 1742 |
| ibm | ds4200 | 1814 |
The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 7.0 |
| ibm | security_appscan_source | 8.0 |
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.0.2 |
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.1.3 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_inotes | 8.5.2.2 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_inotes | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.2.3 |
| ibm | lotus_inotes | 8.5.2.1 |
| ibm | lotus_inotes | 8.5.1.1 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.1.2 |
| ibm | lotus_inotes | 8.5.0.1 |
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr | 8.2 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to the search feature.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2 | 9.7 |
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.1 |
Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.0.0 |
| ibm | smartcloud_control_desk | 7.0 |
Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | smartcloud_control_desk | 7.0 |
IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.0.0 |
| ibm | smartcloud_control_desk | 7.0 |
IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | remote_supervisor_adapter_ii_firmware | 1.3 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.1 |
| ibm | remote_supervisor_adapter_ii_firmware | * |
| ibm | remote_supervisor_adapter_ii_firmware | 1.4 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.0 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.7 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.8 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.12 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.2 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.11 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.5 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.9 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.6 |
| ibm | remote_supervisor_adapter_ii_firmware | 1.10 |
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_hardware_management_console_firmware | 7r3.5.0 |
| ibm | systems_director_management__console_firmware | 6r7.3.0 |
| ibm | power_hardware_management_console_firmware | 7r7.2.0 |
| ibm | power_hardware_management_console_firmware | 7r7.1.0 |
| ibm | power_hardware_management_console_firmware | 7r7.3.0 |
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_directory_server | * |
| ibm | global_security_kit | * |
| ibm | global_security_kit | 7.0.4.29 |
| ibm | tivoli_directory_server | * |
| ibm | global_security_kit | 7.0.4.28 |
The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
Cross-site scripting (XSS) vulnerability in Query Studio in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5.0.6 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.1.0.2 |
| ibm | db2 | 9.5.0.5 |
| ibm | db2 | 9.1.0.1 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.1.0.10 |
| ibm | db2 | 9.1.0.11 |
| ibm | db2 | 9.5.0.1 |
| ibm | db2 | 9.5.0.4 |
| ibm | db2 | 9.5.0.8 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.5.0.7 |
| ibm | db2 | 9.5.0.3 |
| ibm | db2 | 9.1.0.7 |
| ibm | db2 | 9.5.0.9 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.1.0.3 |
| ibm | db2 | 9.1.0.5 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.1.0.6 |
| ibm | db2 | 9.1 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.1.0.4 |
| ibm | db2 | 9.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.1.0.8 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2 | 9.1.0.9 |
IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5.0.6 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.1.0.2 |
| ibm | db2 | 9.5.0.5 |
| ibm | db2 | 9.1.0.1 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.1.0.10 |
| ibm | db2 | 9.1.0.11 |
| ibm | db2 | 9.5.0.1 |
| ibm | db2 | 9.5.0.4 |
| ibm | db2 | 9.5.0.8 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.5.0.7 |
| ibm | db2 | 9.5.0.3 |
| ibm | db2 | 9.1.0.7 |
| ibm | db2 | 9.5.0.9 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.1.0.3 |
| ibm | db2 | 9.1.0.5 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.1.0.6 |
| ibm | db2 | 9.1 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.1.0.4 |
| ibm | db2 | 9.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.1.0.8 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2 | 9.1.0.9 |
Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.5.0.6 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.1.0.2 |
| ibm | db2 | 9.5.0.5 |
| ibm | db2 | 9.1.0.1 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.1.0.10 |
| ibm | db2 | 9.1.0.11 |
| ibm | db2 | 9.5.0.1 |
| ibm | db2 | 9.5.0.4 |
| ibm | db2 | 9.5.0.8 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.5.0.7 |
| ibm | db2 | 9.5.0.3 |
| ibm | db2 | 9.1.0.7 |
| ibm | db2 | 9.5.0.9 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.1.0.3 |
| ibm | db2 | 9.1.0.5 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.1.0.6 |
| ibm | db2 | 9.1 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.1.0.4 |
| ibm | db2 | 9.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.1.0.8 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2 | 9.1.0.9 |
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.1 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.6 |
| ibm | websphere_mq | 7.0.1.4 |
The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_firmware | 2.6 |
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | proventia_network_mail_security_system_firmware | 2.5 |
| ibm | proventia_network_mail_security_system_firmware | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.5 |
| ibm | proventia_network_mail_security_system_firmware | 2.5.1 |
| ibm | lotus_protector_for_mail_security | 2.5.1 |
| ibm | proventia_network_mail_security_system_firmware | 2.5.0.2 |
| ibm | lotus_protector_for_mail_security | 2.1 |
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_directory_server | * |
| ibm | global_security_kit | * |
| ibm | global_security_kit | 7.0.4.29 |
| ibm | tivoli_directory_server | * |
| ibm | global_security_kit | 7.0.4.28 |
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0 |
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.4 |
| ibm | websphere_mq | 7.0.4.0 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.2.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.2.0 |
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | proventia_network_mail_security_system_firmware | 2.6 |
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | proventia_network_mail_security_system_firmware | 2.5 |
| ibm | proventia_network_mail_security_system_firmware | 2.8 |
| ibm | proventia_network_mail_security_system | ms3004 |
| ibm | proventia_network_mail_security_system | * |
| ibm | lotus_protector_for_mail_security | 2.5 |
| ibm | proventia_network_mail_security_system_firmware | 2.5.1 |
| ibm | lotus_protector_for_mail_security | 2.5.1 |
| ibm | proventia_network_mail_security_system_firmware | 2.5.0.2 |
| ibm | lotus_protector_for_mail_security | 2.1 |
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
| ibm | websphere_mq | 7.0.4.0 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.2.2 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq_managed_file_transfer | 7.5 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.2.0 |
IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.1 |
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_hardware_management_console | 7r7.2.0 |
| ibm | power_hardware_management_console | 7r7.1.0 |
| ibm | power_hardware_management_console | 7r7.3.0 |
Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM Tivoli Monitoring 6.2.2 before 6.2.2-TIV-ITM-FP0009 and 6.3.2 before 6.2.3-TIV-ITM-FP0001 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 7.0.2.2 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 7.0.4.0 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 7.0.3.1 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 7.0.1.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 7.0.4.2 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 7.0.2 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 7.0.4.1 |
| ibm | lotus_domino | 7.0.1 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 7.0.3.0 |
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 6.1.0.20 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 6.1.0.24 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 6.1.0.44 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.0.32 |
| ibm | websphere_application_server | 6.1.0.10 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.28 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.36 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.22 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.26 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.42 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.34 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.38 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.16 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_guardium | 8.01 |
| ibm | infosphere_guardium | * |
| ibm | infosphere_guardium | 8.00 |
IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager | 6.2.1.1 |
| ibm | tivoli_federated_identity_manager | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | * |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.1.3 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.11 |
| ibm | tivoli_federated_identity_manager | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager | 6.1.1.12 |
| ibm | tivoli_federated_identity_manager | 6.2.1.2 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.4 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.4 |
The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_guardium | 8.01 |
| ibm | infosphere_guardium | * |
| ibm | infosphere_guardium | 8.00 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.0.0 |
| ibm | smartcloud_control_desk | 7.0 |
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager_business_gateway | 6.1.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.1.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | * |
| ibm | tivoli_federated_identity_manager_business_gateway | * |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | change_and_configuration_management_database | 7.2.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 6.1.0.3 |
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.5 |
| ibm | websphere_message_broker | 6.1.0.10 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 6.1.0.6 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 6.1.0.4 |
| ibm | websphere_message_broker | 6.1.0.9 |
| ibm | websphere_message_broker | 6.1.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_message_broker | 6.1.0.8 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.7 |
| ibm | websphere_message_broker | 6.1.0.1 |
IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web service created with the Rational Business Developer product.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_business_developer | 8.0.1 |
| ibm | rational_business_developer | 8.0.1.2 |
| ibm | rational_business_developer | 8.0.1.1 |
| ibm | rational_business_developer | * |
IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_control_desk | 7.5 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a display name.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | change_and_configuration_management_database | 7.2.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | change_and_configuration_management_database | 7.1. |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2 | * |
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | change_and_configuration_management_database | 6.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_service_desk | 6.2 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | change_and_configuration_management_database | 7.2.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | change_and_configuration_management_database | 7.1. |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden frame footer.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | change_and_configuration_management_database | 7.1. |
| ibm | maximo_asset_management | 7.1 |
| ibm | change_and_configuration_management_database | 7.2.0 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bootable_media_creator | 3.00 |
| ibm | bootable_media_creator | 2.30 |
| ibm | bootable_media_creator | 9.21 |
| ibm | advanced_settings_utility | 9.21 |
| ibm | advanced_settings_utility | 3.70 |
| ibm | advanced_settings_utility | 3.62 |
The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 7.5.1.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 7.0.0.0 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 7.5.1.2 |
| ibm | sametime | 7.5.0.0 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 7.5.1.1 |
| ibm | sametime | 8.5.1.2 |
| ibm | sametime | 6.5.1.0 |
| ibm | sametime | 8.0.1.0 |
CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.70.xc3 |
| ibm | informix_dynamic_server | 11.70.xc2 |
| ibm | informix_dynamic_server | 11.50.xc7 |
| ibm | informix_dynamic_server | 11.50.xc5 |
| ibm | informix_dynamic_server | 11.50.xc5w3 |
| ibm | informix_dynamic_server | 11.50.xc8w1 |
| ibm | informix_dynamic_server | 11.50.xc7w2 |
| ibm | informix_dynamic_server | 11.50.xc7w3 |
| ibm | informix_dynamic_server | 11.50.xc8w4 |
| ibm | informix_dynamic_server | 11.50.xc3 |
| ibm | informix_dynamic_server | 11.50.xc4 |
| ibm | informix_dynamic_server | 11.70.xc1 |
| ibm | informix_dynamic_server | 11.50.xc1 |
| ibm | informix_dynamic_server | 11.50.xc8w2 |
| ibm | informix_dynamic_server | 11.50.xc6w3 |
| ibm | informix_dynamic_server | 11.50.xc9 |
| ibm | informix_dynamic_server | 11.50.xc3w1 |
| ibm | informix_dynamic_server | 11.50.xc6w4 |
| ibm | informix_dynamic_server | 11.50.xc5w4 |
| ibm | informix_dynamic_server | 11.50.xc6 |
| ibm | informix_dynamic_server | 11.70.xc4 |
| ibm | informix_dynamic_server | 11.50.xc8 |
| ibm | informix_dynamic_server | 11.50.xc4w1 |
| ibm | informix_dynamic_server | 11.50.xc6w1 |
| ibm | informix_dynamic_server | 11.50.xc8w3 |
| ibm | informix_dynamic_server | 11.50.xc9w1 |
| ibm | informix_dynamic_server | 11.50.xc5w2 |
| ibm | informix_dynamic_server | 11.50.xc2 |
| ibm | informix_dynamic_server | 11.50.xc6w2 |
| ibm | informix_dynamic_server | 11.50 |
| ibm | informix_dynamic_server | 11.50.xc7w1 |
| ibm | informix_dynamic_server | 11.50.xc7w4 |
IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wizard) access restrictions by visiting context roots in HTTP sessions on port 8080.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_automation_framework | 3.0.0.3 |
| ibm | rational_automation_framework | 3.0.0.4 |
| ibm | rational_automation_framework | 3.0.0.2 |
| ibm | rational_automation_framework | 3.0.0.5 |
| ibm | rational_automation_framework | 3.0 |
| ibm | rational_automation_framework | 3.0.0.1 |
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.1.2.10 |
| ibm | vios | 1.5.1.1 |
| ibm | aix | 6.1 |
| ibm | vios | 2.1.2.12 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
| ibm | vios | 1.5.2.1 |
| ibm | vios | 1.5.2.6 |
| ibm | vios | 2.1.2.13 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | aix | 5.3 |
| ibm | vios | 2.1.3.10 |
| ibm | vios | 1.4.1.2 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.1.0.0 |
| ibm | vios | 2.2.1.0 |
Cross-site scripting (XSS) vulnerability in InfoSphere Business Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console, InfoSphere Administration, and Reporting and Repository Management Web Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_business_glossary | 8.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_business_glossary | 8.1.1 |
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.0 |
| ibm | rational_host_on-demand | 10.0.9.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | rational_change | 5.1 |
| ibm | rational_host_on-demand | 11.0.5.1 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | rational_host_on-demand | 11.0.4.0 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | rational_host_on-demand | 11.0.3.0 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | rational_change | 5.3 |
| ibm | tivoli_monitoring | 6.1.0.7 |
| ibm | rational_host_on-demand | 9.0.8.0 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | lotus_notes | 8.0.2 |
| ibm | rational_host_on-demand | 1.6.0.12 |
| ibm | rational_host_on-demand | 10.0.10.0 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | smart_analytics_system_5600_software | 9.7 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | lotus_domino | 8.5.1.1 |
| tivoli_storage_productivity_center | 5.1 | * |
| ibm | lotus_notes | 8.5.4 |
| ibm | java | * |
| ibm | tivoli_remote_control | 5.1.2 |
| ibm | rational_host_on-demand | 11.0.6.0 |
| ibm | lotus_notes_sametime | 8.0.80407 |
| ibm | websphere_real_time | 2.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | service_delivery_manager | 7.2.2.0 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | websphere_real_time | 3.0 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | rational_host_on-demand | 11.0.5.0 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.6 |
| ibm | smart_analytics_system_5600 | 7200 |
| ibm | tivoli_monitoring | 6.2.1.4 |
| tivoli_storage_productivity_center | 5.1.1 | * |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | rational_change | 4.7 |
| ibm | lotus_notes | 8.0.2.0 |
| tivoli_storage_productivity_center | 5.0 | * |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes_sametime | 8.5.1.20100709-1631 |
| ibm | lotus_notes_traveler | 8.0.1.2 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | rational_host_on-demand | 8.0.8.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | rational_host_on-demand | 11.0.6.1 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.1.0 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | smart_analytics_system_5600_software | - |
| ibm | tivoli_monitoring | 6.1.0 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | service_delivery_manager | 7.2.1.0 |
| ibm | lotus_notes_sametime | 8.0.80822 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | rational_change | 5.2 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | lotus_notes | 8.5 |
| ibm | tivoli_monitoring | 6.2.2.2 |
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.0 |
| ibm | rational_host_on-demand | 10.0.9.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | rational_change | 5.1 |
| ibm | rational_host_on-demand | 11.0.5.1 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | rational_host_on-demand | 11.0.4.0 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | rational_host_on-demand | 11.0.3.0 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | rational_change | 5.3 |
| ibm | tivoli_monitoring | 6.1.0.7 |
| ibm | rational_host_on-demand | 9.0.8.0 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | lotus_notes | 8.0.2 |
| ibm | rational_host_on-demand | 1.6.0.12 |
| ibm | rational_host_on-demand | 10.0.10.0 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | smart_analytics_system_5600_software | 9.7 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | lotus_domino | 8.5.1.1 |
| tivoli_storage_productivity_center | 5.1 | * |
| ibm | lotus_notes | 8.5.4 |
| ibm | java | * |
| ibm | tivoli_remote_control | 5.1.2 |
| ibm | rational_host_on-demand | 11.0.6.0 |
| ibm | lotus_notes_sametime | 8.0.80407 |
| ibm | websphere_real_time | 2.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | service_delivery_manager | 7.2.2.0 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | websphere_real_time | 3.0 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | rational_host_on-demand | 11.0.5.0 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.6 |
| ibm | smart_analytics_system_5600 | 7200 |
| ibm | tivoli_monitoring | 6.2.1.4 |
| tivoli_storage_productivity_center | 5.1.1 | * |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | rational_change | 4.7 |
| ibm | lotus_notes | 8.0.2.0 |
| tivoli_storage_productivity_center | 5.0 | * |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes_sametime | 8.5.1.20100709-1631 |
| ibm | lotus_notes_traveler | 8.0.1.2 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | rational_host_on-demand | 8.0.8.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | rational_host_on-demand | 11.0.6.1 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.1.0 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | smart_analytics_system_5600_software | - |
| ibm | tivoli_monitoring | 6.1.0 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | service_delivery_manager | 7.2.1.0 |
| ibm | lotus_notes_sametime | 8.0.80822 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | rational_change | 5.2 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | lotus_notes | 8.5 |
| ibm | tivoli_monitoring | 6.2.2.2 |
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.0 |
| ibm | rational_host_on-demand | 10.0.9.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | rational_change | 5.1 |
| ibm | rational_host_on-demand | 11.0.5.1 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | rational_host_on-demand | 11.0.4.0 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | rational_host_on-demand | 11.0.3.0 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | rational_change | 5.3 |
| ibm | tivoli_monitoring | 6.1.0.7 |
| ibm | rational_host_on-demand | 9.0.8.0 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | lotus_notes | 8.0.2 |
| ibm | rational_host_on-demand | 1.6.0.12 |
| ibm | rational_host_on-demand | 10.0.10.0 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | smart_analytics_system_5600_software | 9.7 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | lotus_domino | 8.5.1.1 |
| tivoli_storage_productivity_center | 5.1 | * |
| ibm | lotus_notes | 8.5.4 |
| ibm | java | * |
| ibm | tivoli_remote_control | 5.1.2 |
| ibm | rational_host_on-demand | 11.0.6.0 |
| ibm | lotus_notes_sametime | 8.0.80407 |
| ibm | websphere_real_time | 2.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | service_delivery_manager | 7.2.2.0 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | websphere_real_time | 3.0 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | rational_host_on-demand | 11.0.5.0 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.6 |
| ibm | smart_analytics_system_5600 | 7200 |
| ibm | tivoli_monitoring | 6.2.1.4 |
| tivoli_storage_productivity_center | 5.1.1 | * |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | rational_change | 4.7 |
| ibm | lotus_notes | 8.0.2.0 |
| tivoli_storage_productivity_center | 5.0 | * |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes_sametime | 8.5.1.20100709-1631 |
| ibm | lotus_notes_traveler | 8.0.1.2 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | rational_host_on-demand | 8.0.8.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | rational_host_on-demand | 11.0.6.1 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.1.0 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | smart_analytics_system_5600_software | - |
| ibm | tivoli_monitoring | 6.1.0 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | service_delivery_manager | 7.2.1.0 |
| ibm | lotus_notes_sametime | 8.0.80822 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | rational_change | 5.2 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | lotus_notes | 8.5 |
| ibm | tivoli_monitoring | 6.2.2.2 |
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.0 |
| ibm | rational_host_on-demand | 10.0.9.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | rational_change | 5.1 |
| ibm | rational_host_on-demand | 11.0.5.1 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | rational_host_on-demand | 11.0.4.0 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | lotus_notes_traveler | 8.0.1 |
| ibm | lotus_notes_traveler | 8.0.1.3 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | rational_host_on-demand | 11.0.3.0 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | rational_change | 5.3 |
| ibm | tivoli_monitoring | 6.1.0.7 |
| ibm | rational_host_on-demand | 9.0.8.0 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | lotus_notes | 8.0.2 |
| ibm | rational_host_on-demand | 1.6.0.12 |
| ibm | rational_host_on-demand | 10.0.10.0 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | smart_analytics_system_5600_software | 9.7 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | lotus_domino | 8.5.1.1 |
| tivoli_storage_productivity_center | 5.1 | * |
| ibm | lotus_notes | 8.5.4 |
| ibm | java | * |
| ibm | tivoli_remote_control | 5.1.2 |
| ibm | rational_host_on-demand | 11.0.6.0 |
| ibm | lotus_notes_sametime | 8.0.80407 |
| ibm | websphere_real_time | 2.0 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | service_delivery_manager | 7.2.2.0 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | websphere_real_time | 3.0 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | rational_host_on-demand | 11.0.5.0 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.6 |
| ibm | smart_analytics_system_5600 | 7200 |
| ibm | tivoli_monitoring | 6.2.1.4 |
| tivoli_storage_productivity_center | 5.1.1 | * |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_domino | 8.0.2.3 |
| ibm | lotus_domino | 8.0.2.4 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | lotus_domino | 8.0.2 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | rational_change | 4.7 |
| ibm | lotus_notes | 8.0.2.0 |
| tivoli_storage_productivity_center | 5.0 | * |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | lotus_notes_traveler | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes_sametime | 8.5.1.20100709-1631 |
| ibm | lotus_notes_traveler | 8.0.1.2 |
| ibm | lotus_domino | 8.0.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | rational_host_on-demand | 8.0.8.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | rational_host_on-demand | 11.0.6.1 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.1.0 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | smart_analytics_system_5600_software | - |
| ibm | tivoli_monitoring | 6.1.0 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.0 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | service_delivery_manager | 7.2.1.0 |
| ibm | lotus_notes_sametime | 8.0.80822 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.0.1 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | rational_change | 5.2 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | lotus_notes | 8.5 |
| ibm | tivoli_monitoring | 6.2.2.2 |
Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirectURL parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
Multiple cross-site scripting (XSS) vulnerabilities in servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before 8.5.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) userId or (2) address parameter in a getClientConfigFile action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | * |
Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | xiv_storage_system_gen3 | * |
Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal data via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_business_glossary | 8.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_business_glossary | 8.1.1 |
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
IBM Flex System Chassis Management Module (CMM) and Integrated Management Module 2 (IMM2) allow local users to obtain sensitive information about (1) local accounts, (2) SSH private keys, (3) SSL/TLS private keys, (4) SNMPv3 communities, and (5) LDAP credentials by leveraging unspecified side effects of service or maintenance activity.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integrated_management_module_ii | - |
| ibm | flex_system_chassis_management_module | - |
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0 |
| ibm | rational_clearquest | 7.1.2.7 |
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause a denial of service (resource consumption) via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 8.2 |
Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.1.3 |
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5.3 |
IBM Cognos Business Intelligence (BI) 8.4 and 8.4.1 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted request containing a zero-valued byte.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 8.4 |
| ibm | cognos_business_intelligence | 8.4.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (2) Last Name field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_foundations_start | 1.1 |
| ibm | lotus_foundations_start | * |
| ibm | lotus_foundations_start | 1.0 |
| ibm | lotus_foundations_start | 1.2 |
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 7.0.0.4 |
Unspecified vulnerability in the web services framework in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to cause a denial of service (login outage) via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_5_system_firmware | sf240_358_201 |
| ibm | power_5_system_firmware | sf240_415_382 |
| ibm | power_5_system_firmware | sf240_299_201 |
| ibm | power_5_system_firmware | sf240_201_201 |
| ibm | power_5 | 9133-55a |
| ibm | power_5_system_firmware | sf240_284_201 |
| ibm | power_5_system_firmware | sf240_332_201 |
| ibm | power_5 | 9131-52a |
| ibm | power_5_system_firmware | sf240_259_201 |
| ibm | power_5 | 9118-575 |
| ibm | power_5 | 9406-520 |
| ibm | power_5_system_firmware | sf240_222_201 |
| ibm | power_5 | 9115-505 |
| ibm | power_5_system_firmware | sf240_338_201 |
| ibm | power_5_system_firmware | * |
| ibm | power_5 | 9111-520 |
| ibm | power_5_system_firmware | sf240_417 |
| ibm | power_5 | 9406-570 |
| ibm | power_5_system_firmware | sf240_233_201 |
| ibm | power_5_system_firmware | sf240_261_201 |
| ibm | power_5_system_firmware | sf240_298_201 |
| ibm | power_5 | 9110-51a |
| ibm | power_5_system_firmware | sf240_258_201 |
| ibm | power_5 | 9406-550 |
| ibm | power_5_system_firmware | sf240_202_201 |
| ibm | power_5 | 9110-510 |
| ibm | power_5_system_firmware | sf240_403_382 |
| ibm | power_5 | 9405-520 |
| ibm | power_5 | 9116-561 |
| ibm | power_5 | 9406-525 |
| ibm | power_5 | 9111-285 |
| ibm | power_5_system_firmware | sf240_219_201 |
| ibm | power_5_system_firmware | sf240_320_201 |
| ibm | power_5_system_firmware | sf240_382_382 |
| ibm | power_5 | 9123-710 |
| ibm | power_5 | 9113-550 |
| ibm | power_5 | 9117-570 |
| ibm | power_5 | 9124-720 |
| ibm | power_5_system_firmware | sf240_371 |
| ibm | power_5 | 9407-515 |
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.70.xc3 |
| ibm | informix_dynamic_server | 11.70.xc2 |
| ibm | informix_dynamic_server | 11.50.xc7 |
| ibm | informix_dynamic_server | 11.50.xc5 |
| ibm | informix_dynamic_server | 11.50.xc5w3 |
| ibm | informix_dynamic_server | 11.50.xc8w1 |
| ibm | informix_dynamic_server | 11.50.xc7w2 |
| ibm | informix_dynamic_server | 11.50.xc7w3 |
| ibm | informix_dynamic_server | 11.50.xc8w4 |
| ibm | informix_dynamic_server | 11.50.xc3 |
| ibm | informix_dynamic_server | 11.50.xc4 |
| ibm | informix_dynamic_server | 11.70.xc1 |
| ibm | informix_dynamic_server | 11.50.xc1 |
| ibm | informix_dynamic_server | 11.50.xc8w2 |
| ibm | informix_dynamic_server | 11.50.xc6w3 |
| ibm | informix_dynamic_server | 11.50.xc9 |
| ibm | informix_dynamic_server | 11.50.xc3w1 |
| ibm | informix_dynamic_server | 11.50.xc6w4 |
| ibm | informix_dynamic_server | 11.50.xc5w4 |
| ibm | informix_dynamic_server | 11.50.xc6 |
| ibm | informix_dynamic_server | 11.50.xc8 |
| ibm | informix_dynamic_server | 11.50.xc4w1 |
| ibm | informix_dynamic_server | 11.50.xc6w1 |
| ibm | informix_dynamic_server | 11.50.xc8w3 |
| ibm | informix_dynamic_server | 11.50.xc5w2 |
| ibm | informix_dynamic_server | 11.50.xc2 |
| ibm | informix_dynamic_server | 11.50.xc6w2 |
| ibm | informix_dynamic_server | 11.50 |
| ibm | informix_dynamic_server | 11.50.xc7w1 |
| ibm | informix_dynamic_server | 11.50.xc7w4 |
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows local users to read or modify file system objects via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_space_management | 6.1.0 |
| ibm | tivoli_storage_manager_for_space_management | * |
| ibm | tivoli_storage_manager_for_space_management | 6.3.0 |
The web server in InfoSphere Data Replication Dashboard in IBM InfoSphere Replication Server 9.7 and 10.1 through 10.1.0.4 allows remote authenticated users to list directories via a direct request for a directory URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_replication_server | 10.1.0.3 |
| ibm | infosphere_replication_server | 10.1.0.4 |
| ibm | infosphere_replication_server | 9.7 |
| ibm | infosphere_replication_server | 10.1.0.1 |
| ibm | infosphere_replication_server | 10.1.0 |
The Host Connect emulator in IBM Rational Developer for System z 7.1 through 8.5.1 does not properly store the SSL certificate password, which allows local users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_developer_for_system_z | 7.1 |
| ibm | rational_developer_for_system_z | 8.5.0.1 |
| ibm | rational_developer_for_system_z | 8.5.0 |
| ibm | rational_developer_for_system_z | 7.6.2.2 |
| ibm | rational_developer_for_system_z | 8.0.3.3 |
| ibm | rational_developer_for_system_z | 8.0.3.2 |
| ibm | rational_developer_for_system_z | 8.5.1 |
| ibm | rational_developer_for_system_z | 8.0.1.0 |
| ibm | rational_developer_for_system_z | 7.6.2.3 |
| ibm | rational_developer_for_system_z | 8.0.3 |
| ibm | rational_developer_for_system_z | 7.6.2.1 |
| ibm | rational_developer_for_system_z | 7.6.2.4 |
| ibm | rational_developer_for_system_z | 8.0.2 |
| ibm | rational_developer_for_system_z | 8.0.3.1 |
Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via the redirectURL parameter, a different vulnerability than CVE-2012-4824 and CVE-2012-4825.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
| ibm | lotus_notes_traveler | * |
Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers to hijack the authentication of arbitrary users for requests that create problem reports via a getReportProblem upload action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes_traveler | 8.5.1.1 |
| ibm | lotus_notes_traveler | 8.5.3.1 |
| ibm | lotus_notes_traveler | 8.5.3.3 |
| ibm | lotus_notes_traveler | 8.5.3 |
| ibm | lotus_notes_traveler | 8.5.0.0 |
| ibm | lotus_notes_traveler | 8.5.1.3 |
| ibm | lotus_notes_traveler | 8.5.1.2 |
| ibm | lotus_notes_traveler | 8.5.0.1 |
| ibm | lotus_notes_traveler | 8.5.0.2 |
| ibm | lotus_notes_traveler | 8.5.2.1 |
| ibm | lotus_notes_traveler | 8.5.3.2 |
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance | 2.0.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.1 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.3 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.1 |
Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 8.0.0.5 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.2.7 |
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.2.9 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance | 2.0.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.1 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.3 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.1 |
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended administrative-role requirements and perform arbitrary JMX operations via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance | 2.0.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.1 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.3 |
| ibm | websphere_datapower_xc10_appliance | 2.0.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance | 2.1.0.1 |
SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject arbitrary web script or HTML via vectors involving the MHTML protocol.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
Cross-site request forgery (CSRF) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0 |
| ibm | rational_clearquest | 7.1.2.7 |
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Unspecified vulnerability in the web interface on the IBM TS3500 Tape Library with firmware before C260 allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ts3500_tape_library_firmware | * |
| ibm | ts3500_tape_library | 3584 |
IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_modeler | 14.1.0.0 |
| ibm | spss_modeler | 14.0.0.0 |
| ibm | spss_modeler | 14.2.0.1 |
| ibm | spss_modeler | 14.0.0.1 |
| ibm | spss_modeler | 14.2.0.3 |
| ibm | spss_modeler | 14.2.0.0 |
| ibm | spss_modeler | 15.0.0.0 |
| ibm | spss_modeler | 15.0.0.1 |
| ibm | spss_modeler | 14.2.0.2 |
| ibm | spss_modeler | 14.0.0.2 |
| ibm | spss_modeler | 14.1.0.1 |
| ibm | spss_modeler | 14.1.0.2 |
The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_integrator | 5.0 |
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_integrator | 5.1 |
| ibm | sterling_file_gateway | 1.1 |
| ibm | gentran_integration_suite | 4.3 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
| ibm | sterling_file_gateway | 2.0 |
The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
The WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza, when SSL is not enabled, allows remote attackers to discover credentials by sniffing the network during the authentication process.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
Cross-site scripting (XSS) vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza | 6.0.5 |
| ibm | netezza | 6.0.8 |
| ibm | netezza | 7.0 |
Cross-site scripting (XSS) vulnerability in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.1.3 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_inotes | 8.5.2.2 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_inotes | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.2.3 |
| ibm | lotus_inotes | 8.5.2.1 |
| ibm | lotus_inotes | 8.5.1.1 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.1.2 |
| ibm | lotus_inotes | 8.5.0.1 |
| ibm | lotus_inotes | 8.5.3.2 |
Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.0.0 |
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.0.0 |
Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 2.6 |
| ibm | tririga_application_platform | 2.5 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 8.0 |
| ibm | tririga_application_platform | 2.7 |
| ibm | tririga_application_platform | 3.0 |
| ibm | tririga_application_platform | 3.1 |
| ibm | tririga_application_platform | 2.1 |
| ibm | tririga_application_platform | 3.2.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 2.6 |
| ibm | tririga_application_platform | 2.5 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 8.0 |
| ibm | tririga_application_platform | 2.7 |
| ibm | tririga_application_platform | 3.0 |
| ibm | tririga_application_platform | 3.1 |
| ibm | tririga_application_platform | 2.1 |
| ibm | tririga_application_platform | 3.2.1 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users for requests that modify data records via vectors involving (1) the html/en/default/ directory or (2) sqa/html/en/default/process/comm/saveProps.jsp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 2.6 |
| ibm | tririga_application_platform | 2.5 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 8.0 |
| ibm | tririga_application_platform | 2.7 |
| ibm | tririga_application_platform | 3.0 |
| ibm | tririga_application_platform | 3.1 |
| ibm | tririga_application_platform | 2.1 |
| ibm | tririga_application_platform | 3.2.1 |
Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to the normal Unix System Services (USS) security level.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netview | 5.3 |
| ibm | tivoli_netview | 6.1 |
| ibm | tivoli_netview | 5.1 |
| ibm | tivoli_netview | 5.4 |
| ibm | tivoli_netview | 1.4 |
| ibm | tivoli_netview | 5.2 |
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 6.1.0.3 |
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.5 |
| ibm | websphere_message_broker | 6.1.0.10 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_message_broker | 6.1.0.6 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 6.1.0.4 |
| ibm | websphere_message_broker | 6.1.0.9 |
| ibm | websphere_message_broker | 6.1.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_message_broker | 6.1.0.8 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.7 |
| ibm | websphere_message_broker | 6.1.0.11 |
| ibm | websphere_message_broker | 6.1.0.1 |
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 6.1.0.3 |
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.5 |
| ibm | websphere_message_broker | 6.1.0.10 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_message_broker | 6.1.0.6 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 6.1.0.4 |
| ibm | websphere_message_broker | 6.1.0.9 |
| ibm | websphere_message_broker | 6.1.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_message_broker | 6.1.0.8 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.7 |
| ibm | websphere_message_broker | 6.1.0.11 |
| ibm | websphere_message_broker | 6.1.0.1 |
Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows remote attackers to read or modify HSM-managed file system objects via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_space_management | 6.1.0.0 |
| ibm | tivoli_storage_manager_for_space_management | 6.3.0.0 |
| ibm | tivoli_storage_manager_for_space_management | 5.5.0.0 |
| ibm | tivoli_storage_manager_for_space_management | 6.3.0.17 |
| ibm | tivoli_storage_manager_for_space_management | 6.2.0.0 |
| ibm | tivoli_storage_manager_for_space_management | * |
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | - |
| ibm | http_server | 5.3 |
Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka SPR KLYH92XL3W.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| autonomy | keyview_idol | - |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.5.3.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.5.3 |
Cross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 9.4.1.3 |
| ibm | cognos_tm1 | 10.1.0 |
| ibm | cognos_tm1 | * |
| ibm | cognos_tm1 | 9.4.1 |
| ibm | cognos_tm1 | 9.5.1 |
| ibm | cognos_tm1 | 9.5.0 |
The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and disk consumption) via crafted data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect | 4.1.0.0 |
| ibm | sterling_connect | 4.1.0.3 |
| ibm | sterling_connect | 4.1.0.2 |
| ibm | sterling_connect | 4.1.0.1 |
The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | san_volume_controller_software | 6.2.0.0 |
| ibm | san_volume_controller_software | 6.1.0.0 |
| ibm | san_volume_controller_software | 6.3.0.0 |
| ibm | san_volume_controller_software | 6.4.0.0 |
| ibm | storwize_v7000 | - |
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to a work order.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | tivoli_asset_management_for_it | 6.0 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_service_desk | 6.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | change_and_configuration_management_database | 7.2.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | change_and_configuration_management_database | 7.1. |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager | 6.2.1.2 |
Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject arbitrary web script or HTML via event data fields.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | intelligent_operations_center | 1.5.0 |
IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 9.0.0.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.3.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.0.2 |
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted Flash Action Message Format (AMF) messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 8.2 |
| ibm | software_use_analysis | * |
Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli Endpoint Manager (TEM) before 8.2.1372 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 8.0 |
| ibm | tivoli_endpoint_manager | 8.1 |
| ibm | tivoli_endpoint_manager | * |
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 3.6.0 |
| samba | samba | 3.6.4 |
| ibm | storwize | v7000 |
| samba | samba | 3.6.1 |
| samba | samba | 3.6.3 |
| canonical | ubuntu_linux | 12.04 |
| samba | samba | * |
| samba | samba | 3.6.2 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | - |
| ibm | sterling_b2b_integrator | 5.2.4 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to hijack sessions via a modified cookie path.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when login security is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.15 |
Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.13 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | eclipse_help_system | 3.6.2 |
| ibm | spss_data_collection | 6.0 |
| ibm | spss_data_collection | 6.0.1 |
| ibm | spss_data_collection | 7.0 |
| ibm | eclipse_help_system | 3.4.3 |
Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.3 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.0 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.9 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.6 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.1 |
| ibm | webshere_cast_iron_cloud_integration | 6.0.0.0 |
| ibm | webshere_cast_iron_cloud_integration | 6.3.0.0 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.2 |
| ibm | webshere_cast_iron_cloud_integration | 6.1.0.12 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.1 |
IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | data_studio | 3.1.1 |
| ibm | data_studio | 3.1.0 |
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-2983.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza_performance_portal | 1.0.2 |
The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 4.2 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.4.3.3 |
| ibm | tivoli_storage_manager | 4.2.2 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 3.1.0 |
| ibm | tivoli_storage_manager | 6.3.0.0 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.2.2 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.2.5.2 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 5.2.0 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 6.2.0.0 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.4 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.2.4 |
| ibm | tivoli_storage_manager | 4.2.3 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 4.2.4 |
| ibm | tivoli_storage_manager | 5.1.10 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 3.2.1 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain unspecified client access, and consequently obtain unspecified server access, via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 4.2 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.4.3.3 |
| ibm | tivoli_storage_manager | 4.2.2 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 3.1.0 |
| ibm | tivoli_storage_manager | 6.3.0.0 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | 4.2.1 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.2.2 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.2.5.2 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 5.2.0 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 6.2.0.0 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.4 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.2.4 |
| ibm | tivoli_storage_manager | 4.2.3 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 4.2.4 |
| ibm | tivoli_storage_manager | 5.1.10 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 3.2.1 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject arbitrary web script or HTML via a crafted report.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.3 |
The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.3 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_collaboration_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaboration_server | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 6.0.0 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_collaboration_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaboration_server | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 6.0.0 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not properly restrict file types and extensions, which allows remote authenticated users to bypass intended access restrictions via a crafted filename.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggering (1) an error or (2) an exception.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ims_enterprise_suite | 2.2 |
| ibm | ims_enterprise_suite | 1.1 |
| ibm | ims_enterprise_suite | 2.1 |
The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 10.1.0 |
| ibm | cognos_tm1 | 10.1.0.1 |
| ibm | cognos_tm1 | 10.1.1 |
Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 1.4.2 |
| ibm | java | 6.0.0.0 |
Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_guardium | 8.00 |
Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_open_admin_tool | 3.0 |
| ibm | informix_open_admin_tool | 2.0 |
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_b2b_integrator | 5.0 |
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 5.0.0 |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0 |
| ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0.1 |
| ibm | websphere_datapower_integration_appliance_xi52_firmware | 5.0.0 |
| ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0 |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 3.8.2 |
| ibm | websphere_datapower_integration_appliance_xi50_firmware | 5.0.0 |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition | - |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0.2 |
| ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0.2 |
| ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0 |
| ibm | websphere_datapower_integration_appliance_xi52_firmware | 3.8.2 |
| ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0.2 |
| ibm | websphere_datapower_service_gateway_xg45 | - |
| ibm | websphere_datapower_integration_appliance_xi50 | - |
| ibm | websphere_datapower_xc10_appliance_firmware | 4.0.2 |
| ibm | websphere_datapower_integration_appliance_xi50_firmware | 3.8.2 |
| ibm | websphere_datapower_b2b_appliance_xb62_firmware | 3.8.2 |
| ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0.1 |
| ibm | websphere_datapower_b2b_appliance_xb62_firmware | 5.0.0 |
| ibm | websphere_datapower_service_gateway_xg45_firmware | 5.0.0 |
| ibm | websphere_datapower_integration_appliance_xi52 | - |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 5.0.0 |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 5.0.0 |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 3.8.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 4.0 |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0.1 |
| ibm | websphere_datapower_b2b_appliance_xb62 | - |
| ibm | websphere_datapower_service_gateway_xg45_firmware | 3.8.2 |
| ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 4.0.1 |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0 |
| ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0.1 |
| ibm | websphere_datapower_xc10_appliance | - |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 3.8.2 |
| ibm | websphere_datapower_integration_appliance_xi52_virtual_edition | - |
| ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0 |
| ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0 |
| ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0.1 |
| ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0.2 |
| ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0.2 |
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v7000_unified_software | 1.3.2.0 |
| ibm | storwize_v7000_unified_software | 1.3.0.0 |
| ibm | storwize_v7000_unified | - |
| ibm | storwize_v7000_unified_software | 1.3.2.3 |
| ibm | storwize_v7000_unified_software | 1.4.1.1 |
| ibm | storwize_v7000_unified_software | 1.4.0.0 |
| ibm | storwize_v7000_unified_software | 1.4.1.0 |
| ibm | storwize_v7000_unified_software | 1.4.0.4 |
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_disclosure_management | 10.2.0 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_connections | * |
| ibm | lotus_connections | 2.0.0.0 |
| ibm | lotus_connections | 1.0.2.0 |
| ibm | lotus_connections | 2.0.1.1 |
| ibm | lotus_connections | 2.5.0.3 |
| ibm | lotus_connections | 1.0.1.0 |
| ibm | lotus_connections | 2.5.0.2 |
| ibm | lotus_connections | 3.0.1.0 |
| ibm | lotus_connections | 1.0.0.0 |
| ibm | lotus_connections | 3.0.1.1 |
| ibm | lotus_connections | 3.0.0.0 |
| ibm | lotus_connections | 2.5.0.1 |
| ibm | lotus_connections | 2.0.1.0 |
IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_multi-channel_fulfillment_solution | 8.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 8.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.0 |
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_multi-channel_fulfillment_solution | 8.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 8.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.0 |
Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or cause a denial of service via a long line in (1) hrfstable.idx, (2) hrdevice.idx, (3) hrstorage.idx, or (4) lotusmapfile in the SSM Config directory, or (5) .manifest.hive in the main agent directory.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool_application_service_monitors | 4.0.0 |
| ibm | tivoli_netcool_application_service_monitors | 4.0.1 |
| ibm | tivoli_netcool_system_service_monitors | 4.0.0 |
| ibm | tivoli_netcool_system_service_monitors | 4.0.1 |
Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transaction with a long table name that is not properly handled by a packet decoder.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool_application_service_monitors | 4.0.0 |
| ibm | tivoli_netcool_system_service_monitors | 4.0.0 |
IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.5.0.0 |
Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.5.0.0 |
Stack-based buffer overflow in the Manual Explore browser plug-in for Firefox in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to cause a denial of service (plug-in crash) via a crafted web page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.3 |
IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.3 |
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.2.0.0 |
| ibm | sterling_secure_proxy | 3.4.1.0 |
| ibm | sterling_secure_proxy | 3.4.1.6 |
| ibm | sterling_secure_proxy | 3.4.1.2 |
| ibm | sterling_secure_proxy | 3.4.1.5 |
| ibm | sterling_secure_proxy | 3.4.0.0 |
| ibm | sterling_secure_proxy | 3.3.0.1 |
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspecified HTTP header field, which allows remote attackers to obtain potentially sensitive information by reading a version string.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.2.0.0 |
| ibm | sterling_secure_proxy | 3.4.1.0 |
| ibm | sterling_secure_proxy | 3.4.1.6 |
| ibm | sterling_secure_proxy | 3.4.1.2 |
| ibm | sterling_secure_proxy | 3.4.1.5 |
| ibm | sterling_secure_proxy | 3.4.0.0 |
| ibm | sterling_secure_proxy | 3.3.0.1 |
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.2.0.0 |
| ibm | sterling_secure_proxy | 3.4.1.0 |
| ibm | sterling_secure_proxy | 3.4.1.6 |
| ibm | sterling_secure_proxy | 3.4.1.2 |
| ibm | sterling_secure_proxy | 3.4.1.5 |
| ibm | sterling_secure_proxy | 3.4.0.0 |
| ibm | sterling_secure_proxy | 3.3.0.1 |
The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_notes | 8.5.2 |
| ibm | lotus_notes | 9.0 |
IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 5.6.1.3 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 5.6.1.2 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 5.6.1.4 |
| ibm | websphere_commerce | 5.6.1.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 5.6.1 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 5.6.1.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.1.3 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_inotes | 8.5.2.2 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_inotes | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.2.3 |
| ibm | lotus_inotes | 8.5.2.1 |
| ibm | lotus_inotes | 8.5.1.1 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.1.2 |
| ibm | lotus_inotes | 8.5.0.1 |
| ibm | lotus_inotes | 8.5.3.2 |
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | global_console_manager_32_firmware | * |
| ibm | global_console_manager_16_firmware | * |
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect_direct_user_interface | 1.4.0.2 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.7 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.3 |
| ibm | sterling_connect_direct_user_interface | 1.5.0.1 |
| ibm | sterling_connect_direct_user_interface | 1.5.0.0 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.6 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.10 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.0 |
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect_direct_user_interface | 1.4.0.2 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.7 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.3 |
| ibm | sterling_connect_direct_user_interface | 1.5.0.1 |
| ibm | sterling_connect_direct_user_interface | 1.5.0.0 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.6 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.10 |
| ibm | sterling_connect_direct_user_interface | 1.4.0.0 |
The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 6.0.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 6.0.2.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 6.1.1.0 |
| ibm | security_appscan | * |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | security_appscan | 6.0.1.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | rational_policy_tester | 8.0.1.0 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.0.0.0 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | rational_policy_tester | 8.0.1.1 |
| ibm | rational_policy_tester | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | rational_policy_tester | 8.0.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | rational_policy_tester | 8.0.0.2 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.3 |
Cross-site scripting (XSS) vulnerability in the Sametime Links server in IBM Sametime 8.0.2 through 8.5.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5 |
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.1.1 |
| ibm | lotus_sametime | 8.0.2 |
| ibm | lotus_sametime | 8.0.2.1 |
| ibm | lotus_sametime | 8.5.1 |
| ibm | lotus_sametime | 8.5.2.1 |
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.1 |
| ibm | lotus_sametime | 8.5.1.1 |
| ibm | sametime | 8.5.1 |
| ibm | lotus_sametime | 8.5.1.2 |
| ibm | lotus_sametime | 8.5.1 |
| ibm | sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
| ibm | sametime | 8.5.1.2 |
Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | classic_meeting_server | 7.5.1.2 |
| ibm | lotus_sametime | 8.5 |
| ibm | lotus_sametime | 8.5.1.1 |
| ibm | lotus_sametime | 8.0.1 |
| ibm | lotus_sametime | 8.0.2 |
| ibm | lotus_sametime | 8.0.1.1 |
| ibm | lotus_sametime | 8.5.1 |
| ibm | lotus_sametime | 7.5.1.2 |
| ibm | lotus_sametime | 8.5.2.1 |
| ibm | classic_meeting_server | 8.5.1.2 |
| ibm | lotus_sametime | 8.0 |
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.0.2.1 |
| ibm | classic_meeting_server | 8.5 |
| ibm | classic_meeting_server | 8.0.1 |
| ibm | classic_meeting_server | 8.0.2 |
| ibm | classic_meeting_server | 8.5.2.1 |
ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes_traveler | 9.0 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2 |
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in an HTML e-mail message, aka SPRs JMOY95BLM6 and JMOY95BN49.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.0.2.1 |
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.0.0 |
| ibm | lotus_notes | 8.0.2.3 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.0.1 |
| ibm | lotus_notes | 8.0.2.2 |
| ibm | lotus_notes | 8.0.2.4 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.0 |
| ibm | lotus_notes | 8.0.2.0 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_notes | 8.0.2.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 9.0.0.0 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.3.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.0.2.6 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.0.2 |
An unspecified third-party component in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 uses short session ID values, which makes it easier for remote attackers to hijack sessions, and consequently obtain sensitive information, via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | application_manager_for_smart_business | 1.2.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (abend) via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | application_manager_for_smart_business | 1.2.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, Sametime Advanced Connect client, Sametime Advanced Web client, and other products, allows remote authenticated users to send commands to individual chat users, or to all participants in a chat room, via a crafted Sametime Instant Message (IM).
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | lotus_sametime | 8.5.1.1 |
| ibm | lotus_sametime | 8.5.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Unspecified vulnerability in IBM API Management 2.0 before 2.0.0.1 allows remote attackers to access tenant APIs, and consequently obtain sensitive information or modify data, via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 2.0.0.0 |
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2012-5766.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Accelerator JSPs, (2) Organization Administration Console JSPs, and (3) Administration Console JSPs in WebSphere Commerce Tools in IBM WebSphere Commerce 5.6.1.0 through 5.6.1.5, 6.0.0.0 through 6.0.0.11, and 7.0.0.0 through 7.0.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 5.6.1.3 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 5.6.1.2 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 5.6.1.4 |
| ibm | websphere_commerce | 5.6.1.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 5.6.1 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 5.6.1.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and CVE-2013-0475.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0475, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 4.5.0.0 |
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers to obtain sensitive information in opportunistic circumstances by eavesdropping on the broadcast domain. IBM X-Force ID: 83166.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | network_operating_system | - |
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | application_support_facility | 3.4.0 |
| ibm | document_connect_for_application_support_facility | * |
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | application_support_facility | 3.4.0 |
| ibm | document_connect_for_application_support_facility | * |
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass intended access restrictions and create, modify, or delete documents or scripts via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is enabled, do not require administrative credentials, which allows remote authenticated users to obtain sensitive database information via a request to the API tester URI.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.38 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.14 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.2 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.1 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.36 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.11 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.12 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.16 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.23 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.13 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.15 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.28 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.11 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.3 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.10 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.9 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.16 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.2 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.1 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.3 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.6 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.34 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.9 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.7 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.17 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.39 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.27 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.8 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.14 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.4 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.22 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.26 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.41 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.44 |
| ibm | sterling_multi-channel_fulfillment_solution | 8.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.33 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.35 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.43 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.21 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.12 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.24 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.8 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.4 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.7 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.29 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.42 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.6 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.30 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.18 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.32 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.19 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.13 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.25 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.15 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.37 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.31 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.20 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 8.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0.10 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0.40 |
The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attackers to impersonate arbitrary users by leveraging access to a legitimate user's web browser either (1) before or (2) after authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3) portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.12, 6.2.1 before 6.2.1.5, and 6.2.2 before 6.2.2.4 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.12 and 6.2.1 before 6.2.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a SAML 2.0 response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.4 |
| ibm | tivoli_federated_identity_manager | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.11 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.11 |
| ibm | tivoli_federated_identity_manager | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager | 6.2.2.3 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1.4 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1.3 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager | 6.2.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.1.3 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.1.2 |
The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each account requires a password, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_replication_server | 10.1.0.2 |
| ibm | infosphere_replication_server | 10.1.0.3 |
| ibm | infosphere_replication_server | 10.2.0.0 |
| ibm | infosphere_replication_server | 10.1.0.4 |
| ibm | infosphere_replication_server | 9.7 |
| ibm | infosphere_replication_server | 10.1.0.1 |
| ibm | infosphere_replication_server | 10.1.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to the (1) web console and (2) repository management user interfaces.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.0.2 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 5.1.0.4 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.0.0.4 |
| ibm | websphere_portal | 5.1.0.2 |
| ibm | websphere_portal | 5.1.0.3 |
| ibm | websphere_portal | 5.1.0.0 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | * |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.0.0.3 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 5.1.0.5 |
| ibm | websphere_portal | 5.1.0.1 |
IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.0.0.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.0.2.0 |
| ibm | inotes | 8.0.1.0 |
Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0591.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.0.0.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.0.2.0 |
| ibm | inotes | 8.0.1.0 |
Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.0.0 |
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.0.0.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.0.2.0 |
| ibm | inotes | 8.0.1.0 |
Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.1.0.19 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 8.0.0.5 |
| ibm | rational_clearquest | 8.0.0.7 |
| ibm | rational_clearquest | 8.0.1 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.2.7 |
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.11 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.2.9 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.2.10 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0.6 |
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_directory_server | 5.2 |
| ibm | rational_directory_server | 5.2.0.2 |
| ibm | rational_directory_server | * |
| ibm | rational_directory_server | 5.1.1.1 |
| ibm | rational_directory_server | 5.2.0.1 |
| ibm | rational_directory_server | 5.1.1 |
Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.3 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.3 |
| ibm | websphere_datapower_xc10_appliance | - |
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | geronimo | 3.0 |
| ibm | websphere_application_server | 3.0.0.3 |
Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors, aka ZDI-CAN-1802.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_monitor | 9.22 |
| ibm | business_process_monitor | 9.13.1 |
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the number of incorrect authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, related to a stored XSS issue.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session for transmitting login credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.3 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.4.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.3.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 9.1.0 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.5.1 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.1.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 7.2.2 |
| ibm | infosphere_optim_data_growth_for_oracle_e-business_suite | 6.3.2 |
Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (segmentation fault) via a crafted http URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | application_manager_for_smart_business | 1.2.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to perform unspecified redirection of HTTP requests, and bypass the proxy-server configuration, via crafted HTTP traffic.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | application_manager_for_smart_business | 1.2.1 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_transformation_extender | 8.4.0.1 |
| ibm | websphere_transformation_extender | 8.4.0.3 |
| ibm | websphere_transformation_extender | 8.4.0.0 |
| ibm | websphere_transformation_extender | 8.4.0.2 |
Buffer overflow in dsmtca in IBM Tivoli Storage Manager (TSM) through 5.5.4.0, 6.1.0 through 6.1.5.4, 6.2.0 through 6.2.4.7, and 6.3.0 through 6.3.0.17 on UNIX and Linux allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 6.2.4.7 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 5.4.3.3 |
| ibm | tivoli_storage_manager | 6.3.0 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.2.2 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.2.5.2 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 5.2.0 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.4 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.2.4 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 5.1.10 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.5.3 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_control_center | 5.3.0.3 |
| ibm | sterling_control_center | 5.4.0.1 |
| ibm | sterling_control_center | 5.3.0.1 |
| ibm | sterling_control_center | 5.4.0 |
| ibm | sterling_control_center | 5.2.0 |
| ibm | sterling_control_center | 5.3.0 |
| ibm | sterling_control_center | 5.3.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_control_center | 5.3.0.3 |
| ibm | sterling_control_center | 5.4.0.1 |
| ibm | sterling_control_center | 5.3.0.1 |
| ibm | sterling_control_center | 5.4.0 |
| ibm | sterling_control_center | 5.2.0 |
| ibm | sterling_control_center | 5.3.0 |
| ibm | sterling_control_center | 5.3.0.2 |
Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.0.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.0.1 |
IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_cast_iron_cloud_integration | 6.1.0.0 |
| ibm | websphere_cast_iron_cloud_integration | 6.3.0.0 |
| ibm | websphere_cast_iron_cloud_integration | 6.0.0.0 |
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 |
The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 9.0.0.0 |
| ibm | lotus_notes | 8.5.3.4 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_notes | 8.5.3.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
| ibm | lotus_notes | 8.5.3 |
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Directory traversal vulnerability in IBM Optim Performance Manager 4.1.1 and IBM InfoSphere Optim Performance Manager 5.x before 5.2 allows remote authenticated users to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_performance_manager | 5.1.1.1 |
| ibm | infosphere_optim_performance_manager | 5.1.0 |
| ibm | optim_performance_manager | 4.1.1 |
| ibm | infosphere_optim_performance_manager | 5.1.1.0 |
Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | data_studio | 3.1.1 |
| ibm | data_studio | 3.1.0 |
Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | data_studio | 3.1.1 |
| ibm | data_studio | 3.1.0 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to upload arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling File Gateway 2.2 and Sterling B2B Integrator allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2013-0468.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | - |
| ibm | sterling_file_gateway | 2.2 |
Directory traversal vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to read or modify files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2978.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect | 4.1.0.0 |
| ibm | sterling_connect | 3.8.00 |
| ibm | sterling_connect | 4.0.00 |
The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.5 |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user's active session via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 6.0.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 6.0.2.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 6.1.1.0 |
| ibm | security_appscan | * |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | security_appscan | 6.0.1.0 |
frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_data_replication_dashboard | 9.7 |
| ibm | infosphere_data_replication_dashboard | 10.1 |
SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_data_replication_dashboard | 9.7 |
| ibm | infosphere_data_replication_dashboard | 10.1 |
Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_data_replication_dashboard | 9.7 |
| ibm | infosphere_data_replication_dashboard | 10.1 |
Unspecified vulnerability in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 allows remote authenticated users to execute arbitrary commands via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ims_enterprise_suite | 2.2 |
| ibm | ims_enterprise_suite | 1.1 |
| ibm | ims_enterprise_suite | 2.1 |
Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.8 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.10 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.7 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.7 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.8 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.9 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 |
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.2.2 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3008.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 7.0.2.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.4.0 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 7.0.2.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.4.0 |
| ibm | java | 6.0.1.0 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 7.0.2.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.4.0 |
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 5.0.15.0 |
| ibm | java | 1.4.2.13.2 |
| ibm | java | 5.0.16.0 |
| ibm | java | 1.4.2.13.12 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 1.4.2.13.10 |
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.12.2 |
| ibm | java | 5.0.11.2 |
| ibm | java | 1.4.2.13.6 |
| ibm | java | 7.0.4.0 |
| ibm | java | 5.0.11.1 |
| ibm | java | 6.0.10.0 |
| ibm | java | 1.4.2.13 |
| ibm | java | 6.0.8.0 |
| ibm | java | 6.0.9.2 |
| ibm | java | 7.0.1.0 |
| ibm | java | 1.4.2.13.5 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.12.0 |
| ibm | java | 1.4.2.13.15 |
| ibm | java | 6.0.3.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| ibm | java | 5.0.16.1 |
| ibm | java | 6.0.9.0 |
| ibm | java | 1.4.2.13.3 |
| ibm | java | 5.0.16.2 |
| ibm | java | 6.0.8.1 |
| ibm | java | 7.0.4.1 |
| ibm | java | 1.4.2.13.8 |
| ibm | java | 1.4.2.13.17 |
| ibm | java | 1.4.2 |
| ibm | java | 6.0.11.0 |
| ibm | java | 5.0.14.0 |
| ibm | java | 6.0.1.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.13.0 |
| ibm | java | 1.4.2.13.11 |
| ibm | java | 1.4.2.13.7 |
| ibm | java | 1.4.2.13.13 |
| ibm | java | 5.0.12.0 |
| ibm | java | 1.4.2.13.1 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| ibm | java | 1.4.2.13.9 |
| ibm | java | 1.4.2.13.14 |
| ibm | java | 6.0.2.0 |
| ibm | java | 1.4.2.13.4 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.13.0 |
| ibm | java | 1.4.2.13.16 |
| ibm | java | 6.0.9.1 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3007.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 7.0.2.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.4.0 |
| ibm | java | 6.0.1.0 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3012.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 5.0.15.0 |
| ibm | java | 1.4.2.13.2 |
| ibm | java | 5.0.16.0 |
| ibm | java | 1.4.2.13.12 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 1.4.2.13.10 |
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.12.2 |
| ibm | java | 5.0.11.2 |
| ibm | java | 1.4.2.13.6 |
| ibm | java | 7.0.4.0 |
| ibm | java | 5.0.11.1 |
| ibm | java | 6.0.10.0 |
| ibm | java | 1.4.2.13 |
| ibm | java | 6.0.8.0 |
| ibm | java | 6.0.9.2 |
| ibm | java | 7.0.1.0 |
| ibm | java | 1.4.2.13.5 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.12.0 |
| ibm | java | 1.4.2.13.15 |
| ibm | java | 6.0.3.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| ibm | java | 5.0.16.1 |
| ibm | java | 6.0.9.0 |
| ibm | java | 1.4.2.13.3 |
| ibm | java | 5.0.16.2 |
| ibm | java | 6.0.8.1 |
| ibm | java | 7.0.4.1 |
| ibm | java | 1.4.2.13.8 |
| ibm | java | 1.4.2.13.17 |
| ibm | java | 1.4.2 |
| ibm | java | 6.0.11.0 |
| ibm | java | 5.0.14.0 |
| ibm | java | 6.0.1.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.13.0 |
| ibm | java | 1.4.2.13.11 |
| ibm | java | 1.4.2.13.7 |
| ibm | java | 1.4.2.13.13 |
| ibm | java | 5.0.12.0 |
| ibm | java | 1.4.2.13.1 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| ibm | java | 1.4.2.13.9 |
| ibm | java | 1.4.2.13.14 |
| ibm | java | 6.0.2.0 |
| ibm | java | 1.4.2.13.4 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.13.0 |
| ibm | java | 1.4.2.13.16 |
| ibm | java | 6.0.9.1 |
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3011.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 5.0.15.0 |
| ibm | java | 1.4.2.13.2 |
| ibm | java | 5.0.16.0 |
| ibm | java | 1.4.2.13.12 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 1.4.2.13.10 |
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.12.2 |
| ibm | java | 5.0.11.2 |
| ibm | java | 1.4.2.13.6 |
| ibm | java | 7.0.4.0 |
| ibm | java | 5.0.11.1 |
| ibm | java | 6.0.10.0 |
| ibm | java | 1.4.2.13 |
| ibm | java | 6.0.8.0 |
| ibm | java | 6.0.9.2 |
| ibm | java | 7.0.1.0 |
| ibm | java | 1.4.2.13.5 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.12.0 |
| ibm | java | 1.4.2.13.15 |
| ibm | java | 6.0.3.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| ibm | java | 5.0.16.1 |
| ibm | java | 6.0.9.0 |
| ibm | java | 1.4.2.13.3 |
| ibm | java | 5.0.16.2 |
| ibm | java | 6.0.8.1 |
| ibm | java | 7.0.4.1 |
| ibm | java | 1.4.2.13.8 |
| ibm | java | 1.4.2.13.17 |
| ibm | java | 1.4.2 |
| ibm | java | 6.0.11.0 |
| ibm | java | 5.0.14.0 |
| ibm | java | 6.0.1.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.13.0 |
| ibm | java | 1.4.2.13.11 |
| ibm | java | 1.4.2.13.7 |
| ibm | java | 1.4.2.13.13 |
| ibm | java | 5.0.12.0 |
| ibm | java | 1.4.2.13.1 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| ibm | java | 1.4.2.13.9 |
| ibm | java | 1.4.2.13.14 |
| ibm | java | 6.0.2.0 |
| ibm | java | 1.4.2.13.4 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.13.0 |
| ibm | java | 1.4.2.13.16 |
| ibm | java | 6.0.9.1 |
IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging support for weak SSL ciphers. IBM X-Force ID: 84353.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | * |
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | * |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-0568, CVE-2013-0475, and CVE-2013-0567.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | * |
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.5.2 |
Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr_for_domino | 8.1.0 |
| ibm | lotus_quickr_for_domino | 8.5.1 |
| ibm | lotus_quickr_for_domino | 8.2.0 |
Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 9.0.0.0 |
Multiple buffer overflows in mqm programs in IBM WebSphere MQ 7.0.x before 7.0.1.11, 7.1.x before 7.1.0.3, and 7.5.x before 7.5.0.2 on non-Windows platforms allow local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 7.0.0.2 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.1 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.10 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.1.0.1 |
| ibm | websphere_mq | 7.0.1.9 |
| ibm | websphere_mq | 7.0.0.1 |
| ibm | websphere_mq | 7.1.0.2 |
| ibm | websphere_mq | 7.0.1.6 |
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory access and daemon crash) via a call that includes named arguments and default parameter values, but does not include all of the expected arguments.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | soliddb | 6.3.52 |
| ibm | soliddb | 6.3.49 |
| ibm | soliddb | 6.3.39 |
| ibm | soliddb | 6.5.0.7 |
| ibm | soliddb | 6.3.38 |
| ibm | soliddb | 6.3.40 |
| ibm | soliddb | 6.5.0.1 |
| ibm | soliddb | 6.3.48 |
| ibm | soliddb | 7.0.0.3 |
| ibm | soliddb | 6.5.0.2 |
| ibm | soliddb | 6.3.54 |
| ibm | soliddb | 6.3.53 |
| ibm | soliddb | 6.5.0.4 |
| ibm | soliddb | 6.3.33 |
| ibm | soliddb | 6.0.1068 |
| ibm | soliddb | 6.3.34 |
| ibm | soliddb | 6.5.11 |
| ibm | soliddb | 6.5.0.6 |
| ibm | soliddb | 6.0 |
| ibm | soliddb | 6.5.0.8 |
| ibm | soliddb | 6.5.10 |
| ibm | soliddb | 6.3.42 |
| ibm | soliddb | 6.0.1067 |
| ibm | soliddb | 6.5.0.0 |
| ibm | soliddb | 6.5.09 |
| ibm | soliddb | 6.3.47 |
| ibm | soliddb | 7.0.0.1 |
| ibm | soliddb | 6.0.1061 |
| ibm | soliddb | 6.5.0.5 |
| ibm | soliddb | 6.3.37 |
| ibm | soliddb | 6.3.55 |
| ibm | soliddb | 6.5.0.3 |
| ibm | soliddb | 6.0.1064 |
| ibm | soliddb | 6.3.41 |
| ibm | soliddb | 6.0.1066 |
| ibm | soliddb | 6.3.44 |
| ibm | soliddb | 6.0.1065 |
| ibm | soliddb | 7.0.0.2 |
| ibm | soliddb | 6.0.1060 |
| ibm | soliddb | 7.0.0.0 |
| ibm | soliddb | 6.0.1069 |
Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_remote_control | 5.1.2 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | * |
| ibm | infosphere_information_server | 8.7 |
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | * |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.1 |
Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | * |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.1 |
Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | * |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.1 |
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | * |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.1 |
IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijacking attack."
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.0.2 |
| ibm | rational_clearquest | 8.0.0.5 |
| ibm | rational_clearquest | 8.0.0.7 |
| ibm | rational_clearquest | 8.0.1 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1 |
| ibm | rational_clearquest | 8.0 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 7.1.2.7 |
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.1.9 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.11 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.0.1 |
| ibm | rational_clearquest | 7.1.2.9 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.2.10 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 7.1.1 |
| ibm | rational_clearquest | 8.0.0.6 |
Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.3 |
| ibm | rhapsody_design_manager | 3.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rhapsody_design_manager | 3.0.0 |
| ibm | rhapsody_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rhapsody_design_manager | 4.0.2 |
| ibm | rhapsody_design_manager | 4.0.4 |
| ibm | rhapsody_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.3 |
| ibm | rhapsody_design_manager | 3.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rhapsody_design_manager | 3.0.0 |
| ibm | rhapsody_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rhapsody_design_manager | 4.0.2 |
| ibm | rhapsody_design_manager | 4.0.4 |
| ibm | rhapsody_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.1 |
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.1 |
| ibm | db2_connect | 9.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2_connect | 9.8 |
| ibm | db2_connect | 9.7 |
| ibm | smart_analytics_system_7600 | - |
| ibm | db2 | 9.7 |
IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flashcopy_manager | 3.1 |
| ibm | tivoli_storage_flashcopy_manager | - |
| ibm | tivoli_storage_manager_for_mail | - |
| ibm | flashcopy_manager | 2.1 |
| ibm | data_protection | 6.1 |
| ibm | data_protection | 6.3 |
| ibm | flashcopy_manager | 2.2 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | star_command_center | 3.0.1 |
| ibm | star_command_center | 3.0.6 |
| ibm | star_command_center | 3.0.0 |
| ibm | star_command_center | 3.0.5 |
| ibm | star_command_center | 3.0.3 |
| ibm | star_command_center | 3.0.4 |
| ibm | star_command_center | 1.6.1 |
| ibm | star_command_center | 3.0.2 |
| ibm | star_command_center | 3.0.7 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability) by generating a large number of fictitious users to enter a meeting room.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information and technical data via a request to a public page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.0.1.0 |
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_sametime | 8.5.2 |
| ibm | lotus_sametime | 8.5.2.1 |
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN98FLQ2.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | * |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 1.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.2 |
| ibm | infosphere_biginsights | 1.4.0.0 |
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
| ibm | infosphere_biginsights | 1.1.0.0 |
| ibm | infosphere_biginsights | 1.3.0.0 |
| ibm | infosphere_biginsights | 1.2.0.0 |
| ibm | infosphere_biginsights | 1.3.0.1 |
IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 1.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.2 |
| ibm | infosphere_biginsights | 1.4.0.0 |
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
| ibm | infosphere_biginsights | 1.1.0.0 |
| ibm | infosphere_biginsights | 1.3.0.0 |
| ibm | infosphere_biginsights | 1.2.0.0 |
| ibm | infosphere_biginsights | 1.3.0.1 |
Open redirect vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 2.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.2 |
| ibm | infosphere_biginsights | 1.4.0.0 |
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
| ibm | infosphere_biginsights | 1.1.0.0 |
| ibm | infosphere_biginsights | 1.3.0.0 |
| ibm | infosphere_biginsights | 1.2.0.0 |
| ibm | infosphere_biginsights | 1.3.0.1 |
CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 2.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.1 |
| ibm | infosphere_biginsights | 1.1.0.2 |
| ibm | infosphere_biginsights | 1.4.0.0 |
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
| ibm | infosphere_biginsights | 1.1.0.0 |
| ibm | infosphere_biginsights | 1.3.0.0 |
| ibm | infosphere_biginsights | 1.2.0.0 |
| ibm | infosphere_biginsights | 1.3.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Social Media Analytics 1.2 before FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | social_media_analytics | 1.2.0.0 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_command_center | 10.0 |
| ibm | cognos_command_center | * |
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_command_center | 10.0 |
| ibm | cognos_command_center | * |
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | host_on-demand | 11.0.7 |
| ibm | java | 5.0.15.0 |
| suse | linux_enterprise_desktop | 11 |
| ibm | host_on-demand | 11.0.3 |
| ibm | java | 5.0.16.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 7.0.0.0 |
| suse | linux_enterprise_java | 11 |
| ibm | java | 5.0.12.2 |
| apache | xerces2_java | * |
| ibm | sterling_b2b_integrator | 5.2.4 |
| ibm | java | 5.0.11.2 |
| ibm | sterling_file_gateway | 2.1 |
| ibm | host_on-demand | 11.0.6.1 |
| ibm | host_on-demand | 11.0.8 |
| ibm | java | 7.0.4.0 |
| ibm | java | 5.0.11.1 |
| ibm | host_on-demand | 11.0.4 |
| ibm | java | 6.0.10.0 |
| suse | linux_enterprise_server | 10 |
| canonical | ubuntu_linux | 13.04 |
| ibm | java | 6.0.8.0 |
| ibm | host_on-demand | 11.0 |
| ibm | java | 6.0.9.2 |
| canonical | ubuntu_linux | 12.04 |
| ibm | java | 7.0.1.0 |
| ibm | host_on-demand | 11.0.6 |
| suse | linux_enterprise_server | 9 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | host_on-demand | 11.0.5 |
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | host_on-demand | 11.0.5.1 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| canonical | ubuntu_linux | 10.04 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.12.0 |
| ibm | java | 6.0.3.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| suse | linux_enterprise_java | 10 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| oracle | jre | 1.7.0 |
| opensuse | opensuse | 12.2 |
| ibm | java | 5.0.16.1 |
| ibm | host_on-demand | 11.0.1 |
| oracle | jrockit | * |
| ibm | java | 6.0.9.0 |
| suse | linux_enterprise_sdk | 11 |
| ibm | java | 5.0.16.2 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | java | 6.0.8.1 |
| oracle | jdk | 1.6.0 |
| ibm | java | 7.0.4.1 |
| ibm | host_on-demand | 11.0.2 |
| ibm | java | 6.0.11.0 |
| oracle | jre | 1.6.0 |
| ibm | java | 5.0.14.0 |
| ibm | java | 6.0.1.0 |
| suse | linux_enterprise_server | 11 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.13.0 |
| oracle | jdk | 1.7.0 |
| opensuse | opensuse | 12.3 |
| suse | linux_enterprise_desktop | 10 |
| ibm | java | 5.0.12.0 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| ibm | java | 6.0.2.0 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.13.0 |
| ibm | java | 6.0.9.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote authenticated users to inject arbitrary web script or HTML via (1) unspecified input to WebProcess.srv, (2) unspecified input to html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified input in a portalSectionId action to html/en/default/reportTemplate/hGridTopQuery.jsp.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 2.6 |
| ibm | tririga_application_platform | 2.5 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 2.7 |
| ibm | tririga_application_platform | * |
| ibm | tririga_application_platform | 3.0 |
| ibm | tririga_application_platform | 3.1 |
| ibm | tririga_application_platform | 2.1 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified fields.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 6.1.6 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 6.1.3 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.7 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.1 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.1.5 |
| ibm | websphere_application_server | 6.1.14 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.1.13 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
Cross-site scripting (XSS) vulnerability in adv_sw.php in the Advanced Management Module (AMM) with firmware BBET before BBET64G and BPET before BPET64G for IBM BladeCenter systems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module | 1.01 |
| ibm | advanced_management_module | 1.25 |
| ibm | advanced_management_module | 1.32 |
| ibm | advanced_management_module | 1.42 |
| ibm | advanced_management_module | 1.00 |
| ibm | advanced_management_module | 1.36 |
| ibm | advanced_management_module | * |
| ibm | advanced_management_module | 2.50 |
| ibm | advanced_management_module | 2.48 |
| ibm | advanced_management_module | 1.28 |
| ibm | advanced_management_module | 3.54 |
| ibm | advanced_management_module | 1.34 |
| ibm | advanced_management_module | 1.20 |
| ibm | advanced_management_module | 1.26 |
| ibm | advanced_management_module | 2.46 |
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.2.2 |
IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to execute arbitrary SQL commands via a Birt report with a WHERE clause in plain text.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_it_asset_management_for_it | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_service_desk | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1.1.7 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | tivoli_service_request_manager | 7.1.1.11 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | change_and_configuration_management_database | 7.1.1.11 |
| ibm | change_and_configuration_management_database | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.1.7 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_service_desk | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_service_desk | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.11 |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.1.1.7 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified file-inclusion attacks via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_configuration_manager | 2.1 |
| ibm | db2_recovery_expert | 2.0 |
| ibm | optim_performance_manager | 5.1.0 |
| ibm | data_studio_web_console | 3.1.0 |
| ibm | infosphere_optim_configuration_manager | 2.0 |
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_configuration_manager | 2.1 |
| ibm | db2_recovery_expert | 2.0 |
| ibm | optim_performance_manager | 5.1.0 |
| ibm | data_studio_web_console | 3.1.0 |
| ibm | infosphere_optim_configuration_manager | 2.0 |
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_configuration_manager | 2.1 |
| ibm | db2_recovery_expert | 2.0 |
| ibm | optim_performance_manager | 5.1.0 |
| ibm | data_studio_web_console | 3.1.0 |
| ibm | infosphere_optim_configuration_manager | 2.0 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager_node_8731 | - |
| ibm | system_x3650_m3 | - |
| ibm | system_x3650_m4_hd | - |
| ibm | bladecenter | hs23e |
| ibm | system_x3630_m4_hd | - |
| ibm | system_x_idataplex_dx360_m4_server | - |
| ibm | flex_system_x440_compute_node | - |
| ibm | system_x3750_m4 | - |
| ibm | system_x3630_m3 | - |
| ibm | flex_system_manager_node_8734 | - |
| ibm | system_x3250_m4 | - |
| ibm | system_x3630_m4 | - |
| ibm | system_x3650_m4 | - |
| ibm | system_x3550_m2 | - |
| ibm | system_x3500_m3 | - |
| ibm | system_x3550_m4 | - |
| ibm | flex_system_x220_compute_node | - |
| ibm | flex_system_x240_compute_node | - |
| ibm | integrated_management_module_2 | 1.00 |
| ibm | system_x3690_x5 | - |
| ibm | system_x_idataplex_direct_water_cooled_dx360_m4_server | - |
| ibm | system_x3500_m4 | - |
| ibm | system_x3550_m3 | - |
| ibm | integrated_management_module_2 | 2.00 |
| ibm | flex_system_manager_node_7955 | - |
| ibm | system_x3500_m2 | - |
| ibm | system_x3850_x5 | - |
| ibm | system_x3950_x5 | - |
| ibm | bladecenter | hs23 |
| ibm | system_x3300_m4 | - |
| ibm | system_x3650_m2 | - |
| ibm | system_x3530_m4 | - |
| ibm | system_x3100_m4 | - |
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3400_m2 | - |
| ibm | system_x3650_m3 | - |
| ibm | bladecenter | hs23e |
| ibm | system_x_idataplex_dx360_m4_server | - |
| ibm | flex_system_x440_compute_node | - |
| ibm | system_x3750_m4 | - |
| ibm | system_x3400_m3 | - |
| ibm | system_x3630_m3 | - |
| ibm | system_x3250_m4 | - |
| ibm | system_x3630_m4 | - |
| ibm | bladecenter | hs22v |
| ibm | system_x3650_m4 | - |
| ibm | system_x_idataplex_dx360_m2_server | - |
| ibm | bladecenter | hx5 |
| ibm | system_x3550_m2 | - |
| ibm | system_x3250_m3 | - |
| ibm | system_x3500_m3 | - |
| ibm | system_x3550_m4 | - |
| ibm | flex_system_x220_compute_node | - |
| ibm | flex_system_x240_compute_node | - |
| ibm | system_x3200_m3 | - |
| ibm | system_x3690_x5 | - |
| ibm | system_x3500_m4 | - |
| ibm | system_x3550_m3 | - |
| ibm | bladecenter | hs22 |
| ibm | system_x3500_m2 | - |
| ibm | system_x3850_x5 | - |
| ibm | system_x3950_x5 | - |
| ibm | bladecenter | hs23 |
| ibm | system_x3650_m2 | - |
| ibm | system_x_idataplex_dx360_m3_server | - |
| ibm | system_x3530_m4 | - |
| ibm | system_x3100_m4 | - |
| ibm | system_x3620_m3 | - |
The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.5 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2_connect | 9.8 |
| ibm | db2_connect | 9.7 |
| ibm | db2 | 9.7 |
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect | 3.6.0 |
| ibm | sterling_connect | 3.4.0.1 |
| ibm | sterling_connect | 3.5.0.0 |
| ibm | sterling_connect | 3.6.0.1 |
| ibm | sterling_connect | 3.4.0.0 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3400_m2 | - |
| ibm | system_x3650_m3 | - |
| ibm | bladecenter | hs23e |
| ibm | system_x_idataplex_dx360_m4_server | - |
| ibm | flex_system_x440_compute_node | - |
| ibm | system_x3750_m4 | - |
| ibm | system_x3400_m3 | - |
| ibm | system_x3630_m3 | - |
| ibm | system_x3250_m4 | - |
| ibm | system_x3630_m4 | - |
| ibm | bladecenter | hs22v |
| ibm | system_x3650_m4 | - |
| ibm | system_x_idataplex_dx360_m2_server | - |
| ibm | bladecenter | hx5 |
| ibm | system_x3550_m2 | - |
| ibm | system_x3250_m3 | - |
| ibm | system_x3500_m3 | - |
| ibm | system_x3550_m4 | - |
| ibm | flex_system_x220_compute_node | - |
| ibm | flex_system_x240_compute_node | - |
| ibm | system_x3200_m3 | - |
| ibm | system_x3690_x5 | - |
| ibm | system_x3500_m4 | - |
| ibm | system_x3550_m3 | - |
| ibm | bladecenter | hs22 |
| ibm | system_x3500_m2 | - |
| ibm | system_x3850_x5 | - |
| ibm | system_x3950_x5 | - |
| ibm | bladecenter | hs23 |
| ibm | system_x3650_m2 | - |
| ibm | system_x_idataplex_dx360_m3_server | - |
| ibm | system_x3530_m4 | - |
| ibm | system_x3100_m4 | - |
| ibm | system_x3620_m3 | - |
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3400_m2 | - |
| ibm | system_x3650_m3 | - |
| ibm | bladecenter | hs23e |
| ibm | system_x_idataplex_dx360_m4_server | - |
| ibm | flex_system_x440_compute_node | - |
| ibm | system_x3750_m4 | - |
| ibm | system_x3400_m3 | - |
| ibm | system_x3630_m3 | - |
| ibm | system_x3250_m4 | - |
| ibm | system_x3630_m4 | - |
| ibm | bladecenter | hs22v |
| ibm | system_x3650_m4 | - |
| ibm | system_x_idataplex_dx360_m2_server | - |
| ibm | bladecenter | hx5 |
| ibm | system_x3550_m2 | - |
| ibm | system_x3250_m3 | - |
| ibm | system_x3500_m3 | - |
| ibm | system_x3550_m4 | - |
| ibm | flex_system_x220_compute_node | - |
| ibm | flex_system_x240_compute_node | - |
| ibm | system_x3200_m3 | - |
| ibm | system_x3690_x5 | - |
| ibm | system_x3500_m4 | - |
| ibm | system_x3550_m3 | - |
| ibm | bladecenter | hs22 |
| ibm | system_x3500_m2 | - |
| ibm | system_x3850_x5 | - |
| ibm | system_x3950_x5 | - |
| ibm | bladecenter | hs23 |
| ibm | system_x3650_m2 | - |
| ibm | system_x_idataplex_dx360_m3_server | - |
| ibm | system_x3530_m4 | - |
| ibm | system_x3100_m4 | - |
| ibm | system_x3620_m3 | - |
IBM WebSphere Extended Deployment Compute Grid 8.0 before 8.0.0.3 allows remote authenticated users to obtain sensitive information, and consequently bypass intended access restrictions on jobs, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extended_deployment_compute_grid | 8.5.0.0 |
| ibm | websphere_extended_deployment_compute_grid | 8.0.0.0 |
| ibm | websphere_extended_deployment_compute_grid | 8.0.0.1 |
| ibm | websphere_extended_deployment_compute_grid | * |
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176.
CVSS 2.0
Severity: LOW
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | * |
Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.1.0 |
Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-5370.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.2 |
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 4.1.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 5.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.1.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 4.1.1.2 |
| ibm | spss_collaboration_and_deployment_services | 6.0.0.0 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote attackers to inject arbitrary web script or HTML via a crafted link.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytical_decision_management | 6.1.0.0 |
| ibm | spss_analytical_decision_management | 7.0.0.0 |
| ibm | spss_analytical_decision_management | 6.2.0.0 |
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytical_decision_management | 6.1.0.0 |
| ibm | spss_analytical_decision_management | 7.0.0.0 |
| ibm | spss_analytical_decision_management | 6.2.0.0 |
Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytical_decision_management | 6.1.0.0 |
| ibm | spss_analytical_decision_management | 7.0.0.0 |
| ibm | spss_analytical_decision_management | 6.2.0.0 |
Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 9.0.0.0 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4055.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 9.0.0.0 |
Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.35 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.25 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.27 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.37 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.13 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.29 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.33 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.21 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.47 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.43 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.31 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.39 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server_feature_pack_for_web_services | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 7.5 |
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4051.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 9.0.0.0 |
Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server 8.7 through FP2 and 9.1 through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server | 8.7.0.2 |
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.3 |
| ibm | rational_policy_tester | 8.5.0.4 |
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof Jazz Team servers, obtain sensitive information, and modify the client-server data stream via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_policy_tester | 8.5.0.2 |
| ibm | rational_policy_tester | 8.5.0.0 |
| ibm | rational_policy_tester | 8.5.0.1 |
| ibm | rational_policy_tester | 8.5.0.3 |
| ibm | rational_policy_tester | 8.5.0.4 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.3.5 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 9.0.0.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.3.3 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_inotes | 8.5.3.4 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_inotes | 8.5.3.5 |
| ibm | lotus_inotes | 8.5.3.2 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.3.5 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 9.0.0.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.3.3 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_inotes | 8.5.3.4 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_inotes | 8.5.3.5 |
| ibm | lotus_inotes | 8.5.3.2 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.3.5 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_inotes | 9.0.0.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.3.3 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_inotes | 8.5.3.4 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_inotes | 8.5.3.5 |
| ibm | lotus_inotes | 8.5.3.2 |
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.0 |
| ibm | infosphere_information_server | 8.7 |
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.0 |
| ibm | infosphere_information_server | 8.7 |
Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_inotes | - |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.3.1 |
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.3 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.0.2 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1.2 |
Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_monitor | 9.22 |
| ibm | business_process_monitor | 9.13.1 |
IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code by deploying and accessing a service.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytical_decision_management | 6.1.0.0 |
| ibm | spss_analytical_decision_management | 7.0.0.0 |
| ibm | spss_analytical_decision_management | 6.2.0.0 |
Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-4042.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_collaboration_and_deployment_services | 5.0.0 |
| ibm | spss_collaboration_and_deployment_services | 5.0.1 |
| ibm | spss_collaboration_and_deployment_services | 4.2.1 |
| ibm | spss_collaboration_and_deployment_services | 5.0.2 |
The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.4.0 |
| ibm | tivoli_storage_manager | 6.3.1 |
The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 6.1.0.3 |
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.5 |
| ibm | websphere_message_broker | 6.1.0.10 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_message_broker | 6.1.0.6 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 6.1.0.4 |
| ibm | websphere_message_broker | 6.1.0.9 |
| ibm | websphere_message_broker | 6.1.0.2 |
| ibm | websphere_message_broker | 7.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 6.1 |
| ibm | websphere_message_broker | 6.1.0.8 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 6.1.0.7 |
| ibm | websphere_message_broker | 6.1.0.11 |
| ibm | websphere_message_broker | 6.1.0.1 |
The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script, which allows local users to gain privileges by appending commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 8.0.1 |
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 5.0.0.0 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.1.0 |
Cross-site scripting (XSS) vulnerability in IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" attack against an administrative user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v7000_unified_software | 1.3.2.0 |
| ibm | storwize_v7000_unified_software | 1.3.0.0 |
| ibm | storwize_v7000_unified | - |
| ibm | storwize_v7000_unified_software | 1.3.2.3 |
| ibm | storwize_v7000_unified_software | 1.4.1.1 |
| ibm | storwize_v7000_unified_software | 1.4.0.0 |
| ibm | storwize_v7000_unified_software | 1.4.1.0 |
| ibm | storwize_v7000_unified_software | 1.4.0.4 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging incorrect IBM Connections integration.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i | 7.1 |
| ibm | z/os | * |
| ibm | i | 6.1 |
Buffer overflow in IBM Platform Symphony 5.2, 6.1, and 6.1.1 allows remote attackers to cause a denial of service (process crash or hang) via a malformed SOAP request with a large amount of request data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 5.2 |
| ibm | platform_symphony | 6.1 |
| ibm | platform_symphony | 6.1.1 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK5F.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK2X.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.0.0 |
Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 8.5.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | worklight | 5.0.5.0 |
| ibm | worklight | 6.0.0.0 |
| ibm | worklight | 5.0.0.0 |
| ibm | mobile_foundation | 5.0.0.0 |
| ibm | mobile_foundation | 5.0.5.0 |
| ibm | mobile_foundation | 6.0.0.0 |
| ibm | worklight | 5.0.6.0 |
| ibm | mobile_foundation | 5.0.6.0 |
The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 8.5.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 8.5.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.6.1 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.5.2 |
| ibm | rational_focal_point | 6.4 |
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.6.1 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.5.2 |
| ibm | rational_focal_point | 6.4 |
An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote attackers to bypass authentication and obtain "local environment" access via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 5.2 |
| ibm | platform_symphony | 6.1.1 |
| ibm | platform_symphony | 6.1.0 |
The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (remote-administration outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_internet_pass_thru | 2.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | tivoli_asset_management_for_it | 7.1.2 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_service_request_manager | 7.1.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | change_and_configuration_management_database | 7.1.1.12 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.12 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | tivoli_asset_management_for_it | 7.2.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | change_and_configuration_management_database | 7.2.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | tivoli_service_request_manager | 7.2.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | tivoli_service_request_manager | 7.2.1.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | change_and_configuration_management_database | 7.1.2 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to obtain administrative access via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.3 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.0.0.3 |
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.6 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_file_gateway | 2.2 |
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 7.1.2.10 |
Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 7.1.2.10 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_enterprise_single_sign-on | 8.2 |
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_enterprise_single_sign-on | 8.2 |
The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 7.1.2.10 |
IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager | 1.2.0 |
| ibm | flex_system_manager | 1.1.0 |
| ibm | flex_system_manager | 1.3.0 |
| ibm | flex_system_manager | 1.2.1 |
| ibm | flex_system_manager | 1.3.1 |
IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager | 1.3.0 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_virtual_enterprise | 6.1 |
| ibm | websphere_virtual_enterprise | 6.1.1.1 |
| ibm | websphere_virtual_enterprise | 7.0.0.2 |
| ibm | websphere_virtual_enterprise | 7.0.0.1 |
| ibm | websphere_virtual_enterprise | 6.1.1.3 |
| ibm | websphere_virtual_enterprise | 6.1.1.2 |
| ibm | websphere_virtual_enterprise | 6.1.1.5 |
| ibm | websphere_virtual_enterprise | 7.0.0.3 |
| ibm | websphere_virtual_enterprise | 6.1.1 |
| ibm | websphere_virtual_enterprise | 6.1.1.4 |
| ibm | websphere_virtual_enterprise | 7.0 |
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance | - |
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2.5 |
| ibm | tivoli_federated_identity_manager | 6.2.2.7 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2.6 |
| ibm | tivoli_federated_identity_manager | 6.2.2.4 |
| ibm | tivoli_federated_identity_manager | 6.2.2.8 |
| ibm | tivoli_federated_identity_manager | 6.2.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2.3 |
The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remote authenticated users to obtain unspecified access to this component by leveraging this credential information in an environment with applicable component installation details.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.5.0.0 |
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager_business_gateway | 6.1.1 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 |
| ibm | tivoli_federated_identity_manager_business_gateway | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
The Data Growth Solution for JD Edwards EnterpriseOne in IBM InfoSphere Optim 3.0 through 9.1 has hardcoded database credentials, which allows remote authenticated users to obtain sensitive information by reading an unspecified field in an XML document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_optim_data_growth_solution_for_siebel_crm | 3.2.3 |
| ibm | infosphere_optim_data_growth_solution_for_siebel_crm | 3.2 |
| ibm | infosphere_optim_data_growth_solution_for_siebel_crm | 3.2.1 |
| ibm | infosphere_optim_data_growth_solution_for_siebel_crm | 3.2.2 |
| ibm | infosphere_optim_data_growth_solution_for_siebel_crm | 9.1 |
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager | 1.1.0 |
| ibm | flex_system_manager | 1.3.0 |
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.0 |
| ibm | infosphere_information_server | 8.7 |
Cross-site scripting (XSS) vulnerability in the Local Management Interface (LMI) in IBM Security Network Protection on XGS 5100 devices with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_firmware | 5.1 |
| ibm | security_network_protection_firmware | 5.1.1 |
| ibm | security_network_protection_xgs_5100 | - |
Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_express | 9.0 |
| ibm | cognos_express | 10.1 |
| ibm | cognos_express | 10.2.1 |
| ibm | cognos_express | 9.5 |
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_express | 9.0 |
| ibm | cognos_express | 10.1 |
| ibm | cognos_express | 10.2.1 |
| ibm | cognos_express | 9.5 |
IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_express | 9.0 |
| ibm | cognos_express | 10.1 |
| ibm | cognos_express | 10.2.1 |
| ibm | cognos_express | 9.5 |
The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance | - |
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_viewer | 8.0.0 |
| ibm | forms_viewer | 4.0.0 |
| ibm | forms_viewer | 4.0.0.2 |
| ibm | forms_viewer | 8.0.1 |
| ibm | forms_viewer | 4.0.0.1 |
Cross-site scripting (XSS) vulnerability in the Right Click Plugin context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1 Patch 1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and 5.2.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 5.0.0 |
| ibm | filenet_content_manager | 5.1.0 |
| ibm | filenet_content_manager | 5.2.0 |
IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.5.0.0 |
IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_business_process_framework | 4.1.0 |
IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 8.0.11 |
| ibm | security_appscan | 8.6.0.2 |
| ibm | security_appscan | 5.6.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 6.0.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 6.0.2.0 |
| ibm | security_appscan | 8.0.1.0 |
| ibm | security_appscan | 8.0.1.1 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 6.1.1.0 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.5.0.0 |
| ibm | security_appscan | 6.0.1.0 |
IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 6.1 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.5 |
IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a deployer.virtualsystems[#].delete command.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_provisioning | 2.1.0 |
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.1.0 |
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.3 |
| ibm | rhapsody_design_manager | 3.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rhapsody_design_manager | 3.0.0 |
| ibm | rhapsody_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rhapsody_design_manager | 4.0.2 |
| ibm | rhapsody_design_manager | 4.0.4 |
| ibm | rhapsody_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.0 |
| ibm | rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and read communication logs associated with unrelated records, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_remote_control | 5.1.2 |
| ibm | endpoint_manager_for_remote_control | 9.0.1 |
| ibm | endpoint_manager_for_remote_control | 9.0.0 |
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME elements.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.1 |
| ibm | content_navigator | 2.0.2 |
| ibm | content_navigator | 2.0.0 |
The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.0.0 |
| ibm | qradar_security_information_and_event_manager | 7.0.1 |
| ibm | qradar_security_information_and_event_manager | * |
IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 do not properly restrict file types during uploads, which allows remote authenticated users to have an unspecified impact via an invalid type.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_it_asset_management_for_it | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_service_desk | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1.1.7 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | tivoli_service_request_manager | 7.1.1.11 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | change_and_configuration_management_database | 7.1.1.11 |
| ibm | change_and_configuration_management_database | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.1.7 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_service_desk | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | tivoli_service_request_manager | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_service_desk | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.11 |
The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.5 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2_connect | 9.8 |
| ibm | db2_purescale_feature_9.8 | - |
| ibm | db2_connect | 9.7 |
| ibm | db2 | 9.7 |
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | monitoring_agent_for_unix_logs | 6.2.3 |
| ibm | monitoring_server_(ms)_and_shared_libraries_(ax) | 6.2.0 |
| ibm | monitoring_server_(ms)_and_shared_libraries_(ax) | 6.2.1 |
| ibm | monitoring_agent_for_unix_logs | 6.2.1 |
| ibm | monitoring_agent_for_unix_logs | 6.2.2 |
| ibm | monitoring_server_(ms)_and_shared_libraries_(ax) | 6.2.2 |
| ibm | monitoring_server_(ms)_and_shared_libraries_(ax) | 6.2.3 |
| ibm | monitoring_server_(ms)_and_shared_libraries_(ax) | 6.3.0 |
| ibm | monitoring_agent_for_unix_logs | 6.2.0 |
IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, does not encrypt login requests, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6300, CVE-2013-6301, CVE-2013-6320, and CVE-2013-6333.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6301, CVE-2013-6320, and CVE-2013-6333.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6320, and CVE-2013-6333.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_risk_application | 4.9.1 |
| ibm | algo_risk_application | 2.4.2 |
| ibm | algo_risk_application | 2.5.7.1 |
| ibm | algo_risk_application | 4.7.1 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_risk_application | 2.5.5.2 |
| ibm | algo_risk_application | 2.5.6 |
| ibm | algo_risk_application | 2.5.0 |
| ibm | algo_risk_application | 2.5.1 |
| ibm | algo_risk_application | 4.7.0 |
| ibm | algo_risk_application | 2.5.8 |
| ibm | algo_risk_application | 4.8.0 |
| ibm | algo_risk_application | 4.9.0 |
| ibm | algo_risk_application | 2.5.7.2 |
| ibm | algo_risk_application | 4.6.1 |
| ibm | algo_risk_application | 4.5.1 |
| ibm | algo_risk_application | 4.6.0 |
| ibm | algo_risk_application | 2.5.2 |
| ibm | algo_risk_application | 2.5.3 |
| ibm | algo_risk_application | 2.5.4 |
| ibm | algo_risk_application | 2.4.0.1 |
| ibm | algo_risk_application | 4.5.4 |
| ibm | algo_risk_application | 2.5.5 |
| ibm | algo_risk_application | 4.5.2 |
| ibm | algo_risk_application | 2.4.1 |
| ibm | algo_risk_application | 4.5.3 |
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 5.2 |
| ibm | platform_symphony | 6.1.0.1 |
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_740_firmware | 740.10_01ax740_043_042 |
| ibm | power_730 | 8231-e2d |
| ibm | powerlinux_7r1 | 8246-l1d |
| ibm | power_770_firmware | 770.10_01ax770_038_032 |
| ibm | power_750 | 8408-e8d |
| ibm | power_760_firmware | 760.10_ax760_043_043 |
| ibm | power_760_firmware | 760.31_ah760_069_043 |
| ibm | power_740_firmware | 740.20_01ax740_075_042 |
| ibm | power_720 | 8202-e4d |
| ibm | power_770_firmware | 770.21_01ax770_052_032 |
| ibm | power_760_firmware | 760.11_ax760_051_034 |
| ibm | power_740_firmware | 740.15_01ax740_045_042 |
| ibm | power_760_firmware | 760.10_ax760_043_034 |
| ibm | power_ese | 8412-ead |
| ibm | power_760 | 9109-rmd |
| ibm | power_720 | 8202-e4c |
| ibm | power_740_firmware | 740.21_01ax740_077_042 |
| ibm | power_740_firmware | 740.16_01ax740_046_042 |
| ibm | power_740_firmware | 740.40_01ax740_088_042 |
| ibm | power_740_firmware | 740.61_01ax740_112_042 |
| ibm | power_760_firmware | 760.30_ah760_068_043 |
| ibm | powerlinux_7r2 | 8246-l2d |
| ibm | power_795 | 9119-fhb |
| ibm | power_770 | 9117-mmc |
| ibm | power_760_firmware | 760.00_ax760_034_034 |
| ibm | power_760_firmware | 760.30_am760_068_034 |
| ibm | power_740 | 8205-e6c |
| ibm | power_760_firmware | 760.20_am760_062_034 |
| ibm | power_740_firmware | 740.51_01ax740_098_042 |
| ibm | power_770_firmware | 770.00_01al770_032_032 |
| ibm | power_710 | 8268-e1d |
| ibm | power_770 | 9117-mmd |
| ibm | power_770_firmware | 770.20_01ax770_048_032 |
| ibm | power_740_firmware | 740.60_01ax740_110_042 |
| ibm | power_740 | 8205-e6d |
| ibm | power_760_firmware | 760.10_am760_044_034 |
| ibm | power_730 | 8231-e2c |
| ibm | power_780 | 9179-mhd |
| ibm | power_770_firmware | 770.22_01ax770_055_032 |
| ibm | power_780 | 9179-mhc |
| ibm | power_710 | 8231-e1c |
| ibm | power_710 | 8231-e1d |
| ibm | power_760_firmware | 760.20_ah760_062_043 |
| ibm | powerlinux_7r1 | 8246-l1t |
| ibm | power_760_firmware | 760.31_am760_069_034 |
| ibm | powerlinux_7r2 | 8246-l2t |
| ibm | power_740_firmware | 740.00_01ax740_042_042 |
| ibm | power_740_firmware | 740.50_01ax740_095_042 |
| ibm | power_740_firmware | 740.52_01ax740_100_042 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.0.0 |
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 9.1.0.0 |
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 9.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 9.1.0.0 |
SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 9.1.0.0 |
Unspecified vulnerability in IBM Rational Service Tester 8.3.x and 8.5.x before 8.5.1 and Rational Performance Tester 8.3.x and 8.5.x before 8.5.1 allows remote attackers to read arbitrary files via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_performance_tester | 8.3.0.3 |
| ibm | rational_service_tester | 8.3.0.2 |
| ibm | rational_service_tester | 8.5.0.1 |
| ibm | rational_service_tester | 8.3.0.1 |
| ibm | rational_performance_tester | 8.3.0.2 |
| ibm | rational_service_tester | 8.5.0 |
| ibm | rational_service_tester | 8.5.0.2 |
| ibm | rational_performance_tester | 8.3.0 |
| ibm | rational_service_tester | 8.3.0.3 |
| ibm | rational_performance_tester | 8.5.0.1 |
| ibm | rational_performance_tester | 8.5.0 |
| ibm | rational_service_tester | 8.3.0 |
| ibm | rational_performance_tester | 8.3.0.1 |
| ibm | rational_performance_tester | 8.5.0.2 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enterprise_records | 5.1.1 |
| ibm | infosphere_enterprise_records | 4.5.1 |
IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 do not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | enterprise_records | 5.1.1 |
| ibm | infosphere_enterprise_records | 4.5.1 |
IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunistic circumstances by leveraging an error in a Web Content Manager (WCM) context processor.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to bypass intended access restrictions and read content via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and CVE-2013-6333.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | disposal_and_governance_management_for_it | 6.0.2 |
| ibm | atlas_ediscovery_process_management | * |
| ibm | disposal_and_governance_management_for_it | * |
| ibm | atlas_suite | - |
| ibm | global_retention_policy_and_schedule_management | 6.0.2 |
| ibm | atlas_ediscovery_process_management | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | * |
Cross-site scripting (XSS) vulnerability in Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 8.0 before HF128 and 8.5 before HF93 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | 8.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 8.5 |
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_virtual_enterprise | 7.0.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_virtual_enterprise | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_virtual_enterprise | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_virtual_enterprise | 7.0 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_virtual_enterprise | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect_enterprise_http_option | 1.4.00 |
| ibm | sterling_connect_enterprise_http_option | 1.3.02 |
Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web | 6.1.1 |
| ibm | content_manager_ondemand_for_multiplatforms | 8.5 |
| ibm | security_access_manager_for_web | 6.1 |
| ibm | content_manager_ondemand_for_multiplatforms | 9.0 |
| ibm | security_access_manager_for_web | 6.0 |
| ibm | global_security_kit | - |
| ibm | security_access_manager_for_web | 7.0 |
IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.13 |
SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6302.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and CVE-2013-6320.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 4.9.0 |
| ibm | algo_one | 4.7.1 |
| ibm | algo_one | 4.7.0 |
| ibm | algo_one | 4.8.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows remote attackers to bypass intended access restrictions, and visit PolicyAtlas/ResponseDraftServlet (aka the Compliance Questionnaire Save Draft servlet), via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | disposal_and_governance_management_for_it | 6.0.2 |
| ibm | atlas_ediscovery_process_management | * |
| ibm | disposal_and_governance_management_for_it | * |
| ibm | atlas_suite | - |
| ibm | global_retention_policy_and_schedule_management | 6.0.2 |
| ibm | atlas_ediscovery_process_management | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | * |
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
CVSS 2.0
Severity: LOW
Problem Type: CWE-281,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
The Data Protection for VMware component in IBM Tivoli Storage Manager for Virtual Environments (TSMVE) 6.3 through 7.1.0.2 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (disk consumption) via unspecified GUI actions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_virtual_environments | 6.3.2.1 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.4.0.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.4.1.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.3.0.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.3.2.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 7.1.0.2 |
| ibm | tivoli_storage_manager_for_virtual_environments | 7.1.0.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.3.3.0 |
| ibm | tivoli_storage_manager_for_virtual_environments | 7.1.0.1 |
| ibm | tivoli_storage_manager_for_virtual_environments | 6.3.1.0 |
The FlashCopy Manager for VMware component in IBM Tivoli Storage FlashCopy Manager 3.1 through 4.1.0.1 does not properly check authorization for backup and restore operations, which allows local users to obtain sensitive VM data or cause a denial of service (data overwrite or disk consumption) via unspecified GUI actions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_flashcopy_manager | 3.2.0 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.0 |
| ibm | tivoli_storage_flashcopy_manager | 3.2.1 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.1 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0.1 |
The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2_connect | 10.1 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2_connect | 9.8.0.4 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2_connect | 9.8.0.3 |
| ibm | db2 | 9.8 |
| ibm | db2_connect | 9.8 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 9.8.0.5 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
| ibm | db2_purescale_feature_9.8 | - |
| ibm | db2 | 9.8.0.4 |
| ibm | db2_connect | 9.7.0.9 |
The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account names and passwords via use of an unspecified interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module_firmware | 3.64 |
delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_cx | 8.4 |
| ibm | tealeaf_cx | 8.8 |
| ibm | tealeaf_cx | 7.2 |
| ibm | tealeaf_cx | 8.0 |
| ibm | tealeaf_cx | 8.1 |
| ibm | tealeaf_cx | 8.5 |
| ibm | tealeaf_cx | 8.6 |
| ibm | tealeaf_cx | 8.2 |
| ibm | tealeaf_cx | 8.7 |
| ibm | tealeaf_cx | 7.1 |
| ibm | tealeaf_cx | 8.3 |
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_cx | 8.4 |
| ibm | tealeaf_cx | 8.8 |
| ibm | tealeaf_cx | 7.2 |
| ibm | tealeaf_cx | 8.0 |
| ibm | tealeaf_cx | 8.1 |
| ibm | tealeaf_cx | 8.5 |
| ibm | tealeaf_cx | 8.6 |
| ibm | tealeaf_cx | 8.2 |
| ibm | tealeaf_cx | 8.7 |
| ibm | tealeaf_cx | 7.1 |
| ibm | tealeaf_cx | 8.3 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a denial of service or modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.1.0 |
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.0.0 |
The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.0 |
The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary directory.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_dashboard_framework | 7.0.1 |
| ibm | websphere_dashboard_framework | 6.1.5 |
Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0 before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | quickfile | 1.0.0.0 |
| ibm | quickfile | 1.1.0.1 |
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an HTTP POST request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza_performance_portal | 2.0.0.1 |
| ibm | netezza_performance_portal | 2.0.0.2 |
| ibm | netezza_performance_portal | 2.0 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 7.5.1.2 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.0.1.0 |
IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale_client | 8.5.0.2 |
| ibm | websphere_extreme_scale_client | 8.5.0.3 |
| ibm | websphere_extreme_scale_client | 8.6.0.3 |
| ibm | websphere_extreme_scale_client | 8.6.0.2 |
| ibm | websphere_extreme_scale_client | 7.0.0.0 |
| ibm | websphere_extreme_scale_client | 8.6.0.0 |
| ibm | websphere_extreme_scale_client | * |
| ibm | websphere_extreme_scale_client | 8.6.0.1 |
| ibm | websphere_extreme_scale_client | 7.1.1.0 |
| ibm | websphere_extreme_scale_client | 8.5.0.0 |
| ibm | websphere_extreme_scale_client | 8.5.0.1 |
| ibm | websphere_extreme_scale_client | 7.1.0.0 |
| ibm | websphere_extreme_scale_client | 7.1.0.2 |
| ibm | websphere_extreme_scale_client | 7.1.0.3 |
| ibm | websphere_extreme_scale_client | 7.1.1.1 |
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.5 |
IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000_software | 1.4.0.4 |
| ibm | storwize_unified_v7000 | - |
| ibm | storwize_unified_v7000_software | 1.3.0.0 |
| ibm | storwize_unified_v7000_software | 1.3.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.2 |
| ibm | storwize_unified_v7000_software | 1.4.0.5 |
| ibm | storwize_unified_v7000_software | 1.4.2.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.3 |
| ibm | storwize_unified_v7000_software | 1.4.2.1 |
| ibm | storwize_unified_v7000_software | 1.4.1.1 |
| ibm | storwize_unified_v7000_software | 1.4.0.0 |
| ibm | storwize_unified_v7000_software | 1.4.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.1 |
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smartcloud_analytics_log_analysis | 1.1.0 |
| ibm | smartcloud_analytics_log_analysis | 1.2.0 |
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_modeler | * |
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837 allow remote authenticated users to obtain potentially sensitive stack-trace information by triggering a Birt error.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | tivoli_asset_management_for_it | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | tivoli_service_request_manager | 7.1.1.7 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_service_desk | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1 |
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IMG element.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 10.1.0.2 |
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_enterprise_single_sign-on | 8.2 |
Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_p8_business_process_manager | 5.0.0 |
| ibm | filenet_p8_business_process_manager | 5.1.0 |
| ibm | filenet_content_manager | 4.5.1 |
| ibm | filenet_content_manager | 5.0.0 |
| ibm | filenet_case_foundation | 5.2.0 |
| ibm | filenet_p8_business_process_manager | 4.5.1 |
| ibm | filenet_content_manager | 5.1.0 |
| ibm | filenet_content_manager | 4.5.0 |
| ibm | filenet_content_manager | 5.2.0 |
IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_directory_server | - |
| ibm | tivoli_directory_server | - |
| ibm | global_security_kit | 8.5 |
| ibm | global_security_kit | 8.0.13 |
| ibm | global_security_kit | 7.0 |
| ibm | global_security_kit | 7.0.4.29 |
| ibm | global_security_kit | 8.0 |
| ibm | global_security_kit | 7.0.4.28 |
Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6749.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr_for_domino | 8.5.1 |
Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6748.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_quickr_for_domino | 8.5.1 |
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| juniper | junos_space | * |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | jre | 1.7.0 |
| ibm | forms_viewer | * |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.8.0 |
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| juniper | junos_space | * |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 14.04 |
| oracle | jre | 1.7.0 |
| ibm | forms_viewer | * |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-0432 and CVE-2014-2402.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 14.04 |
| oracle | jre | 1.7.0 |
| ibm | forms_viewer | * |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| juniper | junos_space | * |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| juniper | junos_space | * |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, aka SPR KLYH9F4S2Z.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_domino | 8.5.3.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.1.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_domino | 8.5.1.3 |
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140321-1336 and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via an attachment URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_it_asset_management_for_it | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.8 |
| ibm | change_and_configuration_management_database | 7.1.1.7 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | change_and_configuration_management_database | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.1.7 |
| ibm | maximo_service_desk | 7.1.1.12 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.8 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.1.1.8 |
| ibm | tivoli_service_request_manager | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_service_desk | 7.1.1.7 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_service_desk | 7.1.1.8 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140321-1336 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.12 IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via a crafted report parameter.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_it_asset_management_for_it | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | change_and_configuration_management_database | 7.0 |
| ibm | tivoli_service_request_manager | 7.0 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_service_desk | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1.1.7 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | tivoli_service_request_manager | 7.1.1.11 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | tivoli_service_request_manager | 7.1.0.0 |
| ibm | change_and_configuration_management_database | 7.1.1.11 |
| ibm | change_and_configuration_management_database | 7.1.1.12 |
| ibm | tivoli_service_request_manager | 7.1.1.7 |
| ibm | maximo_service_desk | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | tivoli_service_request_manager | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_service_desk | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | tivoli_it_asset_management_for_it | 7.1.1.11 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Workload Replay 1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | optim_workload_replay | 1.1 |
Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 7.0.0.7 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.0.0.9 |
| ibm | rational_clearcase | 7.0.1.1 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.0.1 |
| ibm | rational_clearcase | 7.0.1.10 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.0.0.6 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 7.0.1.7 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.0 |
| ibm | rational_clearcase | 7.0.0.5 |
| ibm | rational_clearcase | 7.0.1.4 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.0.1.9 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.0.0.3 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 7.0.0.8 |
| ibm | rational_clearcase | 7.1.2.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 7.0.1.6 |
| ibm | rational_clearcase | 7.0.1.3 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.0.0.4 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.0.1.11 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.0.1.8 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 7.0.1.2 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.0.1.5 |
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.0.0.2 |
| ibm | financial_transaction_manager | 2.0.0.0 |
| ibm | financial_transaction_manager | 2.0.0.1 |
| ibm | financial_transaction_manager | 2.1.0.0 |
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.0.0.2 |
| ibm | financial_transaction_manager | 2.0.0.0 |
| ibm | financial_transaction_manager | 2.0.0.1 |
Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.0.0.2 |
| ibm | financial_transaction_manager | 2.0.0.0 |
| ibm | financial_transaction_manager | 2.0.0.1 |
The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.0.0.2 |
| ibm | financial_transaction_manager | 2.0.0.0 |
| ibm | financial_transaction_manager | 2.0.0.1 |
IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.4.0.7 |
| ibm | general_parallel_file_system | 3.4.0.16 |
| ibm | general_parallel_file_system | 3.5.0.0 |
| ibm | general_parallel_file_system | 3.4.0.12 |
| ibm | general_parallel_file_system | 3.4.0.2 |
| ibm | general_parallel_file_system | 3.4.0.27 |
| ibm | general_parallel_file_system | 3.4.0.8 |
| ibm | general_parallel_file_system | 3.4.0.10 |
| ibm | general_parallel_file_system | 3.4.0.13 |
| ibm | general_parallel_file_system | 3.4.0.4 |
| ibm | general_parallel_file_system | 3.4.0.14 |
| ibm | general_parallel_file_system | 3.4.0.23 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 3.5.0.14 |
| ibm | general_parallel_file_system | 3.5.0.10 |
| ibm | general_parallel_file_system | 3.4.0.17 |
| ibm | general_parallel_file_system | 3.4.0.19 |
| ibm | general_parallel_file_system | 3.4.0.22 |
| ibm | general_parallel_file_system | 3.5.0.4 |
| ibm | general_parallel_file_system | 3.5.0.16 |
| ibm | general_parallel_file_system | 3.5.0.15 |
| ibm | general_parallel_file_system | 3.4.0.5 |
| ibm | general_parallel_file_system | 3.4.0.15 |
| ibm | general_parallel_file_system | 3.5.0.2 |
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | general_parallel_file_system | 3.4.0.0 |
| ibm | general_parallel_file_system | 3.4.0.25 |
| ibm | general_parallel_file_system | 3.4.0.3 |
| ibm | general_parallel_file_system | 3.4.0.20 |
| ibm | general_parallel_file_system | 3.5.0.12 |
| ibm | general_parallel_file_system | 3.4.0.24 |
| ibm | general_parallel_file_system | 3.5.0.6 |
| ibm | general_parallel_file_system | 3.5.0.13 |
| ibm | general_parallel_file_system | 3.5.0.8 |
| ibm | general_parallel_file_system | 3.4.0.11 |
| ibm | general_parallel_file_system | 3.4.0.6 |
| ibm | general_parallel_file_system | 3.4.0.18 |
| ibm | general_parallel_file_system | 3.4.0.26 |
| ibm | general_parallel_file_system | 3.4.0.9 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | general_parallel_file_system | 3.4.0.21 |
| ibm | general_parallel_file_system | 3.5.0.7 |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify console Auto Update settings.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | * |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | * |
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | * |
The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | * |
IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.4.0.1 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.4.1.2 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.5.0.2 |
| ibm | rational_focal_point | 6.5.1.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.0.1 |
| ibm | rational_focal_point | 6.4.1.1 |
| ibm | rational_focal_point | 6.4.1.0 |
| ibm | rational_focal_point | 6.5.2 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.4.0.1 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.4.1.2 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.5.0.2 |
| ibm | rational_focal_point | 6.5.1.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.0.1 |
| ibm | rational_focal_point | 6.4.1.1 |
| ibm | rational_focal_point | 6.4.1.0 |
| ibm | rational_focal_point | 6.5.2 |
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.
CVSS 2.0
Severity: LOW
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.2 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.4.1 |
The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.4.0.1 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.4.1.2 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.5.0.2 |
| ibm | rational_focal_point | 6.5.1.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.0.1 |
| ibm | rational_focal_point | 6.4.1.1 |
| ibm | rational_focal_point | 6.4.1.0 |
| ibm | rational_focal_point | 6.5.2 |
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.4.0.1 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.4.1.2 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.5.0.2 |
| ibm | rational_focal_point | 6.5.1.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.0.1 |
| ibm | rational_focal_point | 6.4.1.1 |
| ibm | rational_focal_point | 6.4.1.0 |
| ibm | rational_focal_point | 6.5.2 |
Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
The (1) ssl.conf and (2) httpd.conf files in the Apache HTTP Server component in IBM Netezza Performance Portal 2.0 before 2.0.0.4 have weak SSLCipherSuite values, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | netezza_performance_portal | 2.0.0.1 |
| ibm | netezza_performance_portal | 2.0.0.2 |
| ibm | netezza_performance_portal | 2.0.0.0 |
| ibm | netezza_performance_portal | 2.0.0.3 |
IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_reference_data_management_hub | 10.1 |
| ibm | infosphere_master_data_management_reference_data_management_hub | 11.0 |
IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_soa_appliance | - |
| ibm | websphere_datapower_soa_appliance_firmware | 5.0.0 |
| ibm | websphere_datapower_soa_appliance_firmware | 6.0.0 |
| ibm | websphere_datapower_soa_appliance_firmware | 6.0.1 |
| ibm | websphere_datapower_soa_appliance_firmware | * |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_focal_point | 6.4.1.3 |
| ibm | rational_focal_point | 6.5.1 |
| ibm | rational_focal_point | 6.5.2.2 |
| ibm | rational_focal_point | 6.4.0.1 |
| ibm | rational_focal_point | 6.5.2.1 |
| ibm | rational_focal_point | 6.5 |
| ibm | rational_focal_point | 6.5.2.3 |
| ibm | rational_focal_point | 6.4.1.2 |
| ibm | rational_focal_point | 6.6.0.1 |
| ibm | rational_focal_point | 6.4 |
| ibm | rational_focal_point | 6.5.0.2 |
| ibm | rational_focal_point | 6.5.1.1 |
| ibm | rational_focal_point | 6.6 |
| ibm | rational_focal_point | 6.5.0.1 |
| ibm | rational_focal_point | 6.4.1.1 |
| ibm | rational_focal_point | 6.4.1.0 |
| ibm | rational_focal_point | 6.5.2 |
The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections_portlets | 4.5.1 |
| ibm | connections_portlets | 4.0 |
| ibm | connections_portlets | 4.5 |
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restrictions and conduct deleteAction attacks via a modified URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.1 |
| ibm | content_navigator | 2.0.2 |
| ibm | content_navigator | 2.0.0 |
The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integrated_management_module | - |
| ibm | advanced_management_module | - |
| ibm | integrated_management_module_firmware | * |
| ibm | integrated_management_module_ii_firmware | * |
| ibm | advanced_management_module_firmware | * |
| ibm | integrated_management_module_ii | - |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 8.4.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 3.0.1.2 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.5 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified security tool.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 10.2.2 |
| ibm | cognos_tm1 | 10.1.1.2 |
| ibm | cognos_tm1 | 10.2.0.2 |
| ibm | cognos_tm1 | 9.5.2.3 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algo_credit_limits | 4.5.0 |
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI, as demonstrated by the \x00 character.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 9.0.1 |
| ibm | infosphere_master_data_management_server | 10.0 |
| ibm | infosphere_master_data_management_server | 8.5 |
| ibm | infosphere_master_data_management_server | 9.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.1 |
| ibm | content_navigator | 2.0.2 |
| ibm | content_navigator | 2.0.0 |
Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000_software | 1.4.0.4 |
| ibm | storwize_unified_v7000 | - |
| ibm | storwize_unified_v7000_software | 1.3.0.0 |
| ibm | storwize_unified_v7000_software | 1.4.3.2 |
| ibm | storwize_unified_v7000_software | 1.3.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.2 |
| ibm | storwize_unified_v7000_software | 1.4.0.5 |
| ibm | storwize_unified_v7000_software | 1.4.2.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.3 |
| ibm | storwize_unified_v7000_software | 1.4.2.1 |
| ibm | storwize_unified_v7000_software | 1.4.3.1 |
| ibm | storwize_unified_v7000_software | 1.4.1.1 |
| ibm | storwize_unified_v7000_software | 1.4.0.0 |
| ibm | storwize_unified_v7000_software | 1.4.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.3.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.1 |
Buffer overflow in the Java GUI Configuration Wizard and Preferences Editor in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.2.5.2, 6.3.x before 6.3.2, and 6.4.x before 6.4.2 on Windows and OS X allows local users to cause a denial of service (application crash or hang) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 6.4.0 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0 |
IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page and then following a generated link.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 10.2.0.2 |
| ibm | cognos_tm1 | 10.2.2.0 |
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java_sdk | 6.0.4.0 |
| ibm | java_sdk | 5.0.11.2 |
| ibm | java_sdk | 7.0.6.1 |
| ibm | java_sdk | 6.0.9.0 |
| ibm | java_sdk | 7.0.2.0 |
| ibm | java_sdk | 7.0.4.2 |
| ibm | java_sdk | 7.0.4.0 |
| ibm | java_sdk | 5.0.12.2 |
| ibm | java_sdk | 6.0.13.0 |
| ibm | java_sdk | 6.0.13.1 |
| ibm | java_sdk | 6.0.15.0 |
| ibm | java_sdk | 5.0.11.1 |
| ibm | java_sdk | 6.0.5.0 |
| ibm | java_sdk | 6.0.9.2 |
| ibm | java_sdk | 5.0.12.4 |
| ibm | java_sdk | 6.0.3.0 |
| ibm | java_sdk | 6.0.6.0 |
| ibm | java_sdk | 5.0.12.0 |
| ibm | java_sdk | 5.0.16.1 |
| ibm | java_sdk | 6.0.0.0 |
| ibm | java_sdk | 6.0.1.0 |
| ibm | java_sdk | 5.0.16.0 |
| ibm | java_sdk | 6.0.11.0 |
| ibm | java_sdk | 5.0.12.5 |
| ibm | java_sdk | 6.0.8.1 |
| ibm | java_sdk | 5.0.11.0 |
| ibm | java_sdk | 6.0.10.1 |
| ibm | java_sdk | 7.0.1.0 |
| ibm | java_sdk | 5.0.14.0 |
| ibm | java_sdk | 5.0.13.0 |
| ibm | java_sdk | 7.0.3.0 |
| ibm | java_sdk | 6.0.10.0 |
| ibm | java_sdk | 5.0.16.2 |
| ibm | java_sdk | 6.0.12.0 |
| ibm | java_sdk | 5.0.12.3 |
| ibm | java_sdk | 6.0.15.1 |
| ibm | java_sdk | 5.0.0.0 |
| ibm | java_sdk | 5.0.15.0 |
| ibm | java_sdk | 7.0.5.0 |
| ibm | java_sdk | 6.0.14.0 |
| ibm | java_sdk | 6.0.8.0 |
| ibm | java_sdk | 6.0.2.0 |
| ibm | java_sdk | 7.0.6.0 |
| ibm | java_sdk | 7.0.4.1 |
| ibm | java_sdk | 6.0.13.2 |
| ibm | java_sdk | 5.0.16.5 |
| ibm | java_sdk | 7.1.0.0 |
| ibm | java_sdk | 6.0.7.0 |
| ibm | java_sdk | 6.0.9.1 |
| ibm | java_sdk | 5.0.16.4 |
| ibm | java_sdk | 5.0.12.1 |
| ibm | java_sdk | 5.0.16.3 |
| ibm | java_sdk | 7.0.0.0 |
Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap_taskmaster_capture | 8.0.1 |
| ibm | datacap_taskmaster_capture | 8.1 |
IBM SAN Volume Controller; Storwize V3500, V3700, V5000, and V7000; and Flex System V7000 with software 6.3 and 6.4 before 6.4.1.8, and 7.1 and 7.2 before 7.2.0.3, allow remote attackers to obtain CLI access, and consequently cause a denial of service, via unspecified traffic to the administrative IP address.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_software | 7.1.0.5 |
| ibm | storwize_v3500_software | 6.4.1.1 |
| ibm | san_volume_controller_software | 6.2.0.5 |
| ibm | storwize_v3700_software | 7.1.0.0 |
| ibm | storwize_v7000_software | 6.4.1.3 |
| ibm | storwize_v7000_software | 7.1.0.3 |
| ibm | san_volume_controller_software | 7.1.0.2 |
| ibm | storwize_v3700_software | 7.2.0.0 |
| ibm | storwize_v7000_software | 6.4.1.7 |
| ibm | flex_system_v7000_software | 6.4.1.6 |
| ibm | storwize_v3500_software | 7.1.0.3 |
| ibm | storwize_v7000_software | 6.3.0.6 |
| ibm | storwize_v3700_software | 6.4.1.3 |
| ibm | san_volume_controller_software | 7.1.0.6 |
| ibm | storwize_v5000_software | 7.2.0.1 |
| ibm | storwize_v3500_software | 6.4.1.4 |
| ibm | storwize_v7000_software | 6.4.1.4 |
| ibm | storwize_v7000_software | 6.4.1.5 |
| ibm | storwize_v3700_software | 7.1.0.3 |
| ibm | san_volume_controller_software | 7.1.0.0 |
| ibm | storwize_v3700_software | 6.4.1.5 |
| ibm | san_volume_controller_software | 6.4.0.2 |
| ibm | san_volume_controller_software | 7.1.0.1 |
| ibm | san_volume_controller_software | 7.1.0.3 |
| ibm | san_volume_controller_software | 6.1.0.9 |
| ibm | flex_system_v7000_software | 6.4.1.7 |
| ibm | san_volume_controller_software | 6.2.0.3 |
| ibm | storwize_v7000_software | 6.4.1.6 |
| ibm | flex_system_v7000_software | 7.1.0.1 |
| ibm | san_volume_controller_software | 6.1.0.5 |
| ibm | storwize_v7000_software | 6.4.0.0 |
| ibm | storwize_v3500_software | 7.1.0.2 |
| ibm | san_volume_controller_software | 7.2.0.1 |
| ibm | storwize_v3500_software | 7.1.0.6 |
| ibm | flex_system_v7000_software | 7.1.0.5 |
| ibm | storwize_v5000_software | 7.1.0.7 |
| ibm | storwize_v3700_software | 7.1.0.2 |
| ibm | san_volume_controller_software | 6.1.0.3 |
| ibm | storwize_v3700_software | 7.1.0.5 |
| ibm | storwize_v3500_software | 7.2.0.2 |
| ibm | san_volume_controller_software | 6.1.0.4 |
| ibm | san_volume_controller_software | 6.2.0.1 |
| ibm | san_volume_controller_software | 6.4.1.6 |
| ibm | storwize_v3500_software | 6.4.1.3 |
| ibm | san_volume_controller | - |
| ibm | flex_system_v7000_software | 6.4.1.3 |
| ibm | san_volume_controller_software | 6.3.0.3 |
| ibm | san_volume_controller_software | 6.3.0.2 |
| ibm | storwize_v5000_software | 7.1.0.4 |
| ibm | storwize_v7000_software | 6.3.0.7 |
| ibm | storwize_v3700_software | 7.1.0.1 |
| ibm | san_volume_controller_software | 6.4.0.4 |
| ibm | storwize_v3500_software | 6.4.1.2 |
| ibm | storwize_v3500_software | 7.1.0.1 |
| ibm | storwize_v7000_software | 7.1.0.5 |
| ibm | storwize_v7000_software | 7.1.0.2 |
| ibm | flex_system_v7000 | - |
| ibm | storwize_v5000_software | 7.2.0.0 |
| ibm | san_volume_controller_software | 6.1.0.6 |
| ibm | san_volume_controller_software | 6.4.0.1 |
| ibm | storwize_v3500_software | 6.4.1.7 |
| ibm | flex_system_v7000_software | 6.4.1.2 |
| ibm | storwize_v7000_software | 7.2.0.2 |
| ibm | san_volume_controller_software | 6.1.0.0 |
| ibm | flex_system_v7000_software | 7.2.0.1 |
| ibm | san_volume_controller_software | 6.3.0.1 |
| ibm | storwize_v7000_software | 6.3.0.4 |
| ibm | storwize_v7000_software | 7.2.0.1 |
| ibm | flex_system_v7000_software | 7.2.0.2 |
| ibm | storwize_v5000_software | 7.1.0.2 |
| ibm | san_volume_controller_software | 6.1.0.10 |
| ibm | san_volume_controller_software | 6.4.1.7 |
| ibm | storwize_v3700_software | 6.4.1.4 |
| ibm | san_volume_controller_software | 6.4.1.2 |
| ibm | san_volume_controller_software | 6.3.0.5 |
| ibm | san_volume_controller_software | 6.4.1.3 |
| ibm | storwize_v3700_software | 6.4.1.1 |
| ibm | storwize_v7000_software | 6.4.0.1 |
| ibm | storwize_v3700_software | 6.4.1.7 |
| ibm | storwize_v3700 | - |
| ibm | san_volume_controller_software | 6.4.1.4 |
| ibm | storwize_v3700_software | 7.1.0.6 |
| ibm | san_volume_controller_software | 7.1.0.5 |
| ibm | flex_system_v7000_software | 6.4.1.4 |
| ibm | san_volume_controller_software | 6.4.0.3 |
| ibm | storwize_v7000_software | 6.3.0.2 |
| ibm | storwize_v3500_software | 6.4.1.6 |
| ibm | storwize_v7000_software | 7.1.0.6 |
| ibm | storwize_v7000_software | 6.4.0.4 |
| ibm | flex_system_v7000_software | 7.2.0.0 |
| ibm | san_volume_controller_software | 6.2.0.4 |
| ibm | san_volume_controller_software | 6.1.0.2 |
| ibm | storwize_v7000_software | 6.4.1.2 |
| ibm | san_volume_controller_software | 6.2.0.2 |
| ibm | storwize_v5000_software | 7.2.0.2 |
| ibm | storwize_v3500_software | 7.2.0.0 |
| ibm | storwize_v3700_software | 7.1.0.7 |
| ibm | storwize_v7000_software | 6.4.1.1 |
| ibm | storwize_v3500 | - |
| ibm | flex_system_v7000_software | 6.4.1.5 |
| ibm | storwize_v3700_software | 6.4.1.0 |
| ibm | san_volume_controller_software | 6.4.1.1 |
| ibm | san_volume_controller_software | 6.3.0.4 |
| ibm | flex_system_v7000_software | 7.1.0.3 |
| ibm | san_volume_controller_software | 6.1.0.1 |
| ibm | storwize_v3700_software | 7.2.0.2 |
| ibm | storwize_v5000_software | 7.1.0.6 |
| ibm | san_volume_controller_software | 6.2.0.0 |
| ibm | storwize_v3500_software | 6.4.1.0 |
| ibm | storwize_v7000_software | 7.1.0.0 |
| ibm | storwize_v7000_software | 7.1.0.1 |
| ibm | storwize_v3500_software | 7.1.0.0 |
| ibm | san_volume_controller_software | 6.4.1.5 |
| ibm | storwize_v3700_software | 7.2.0.1 |
| ibm | san_volume_controller_software | 6.2.0.6 |
| ibm | san_volume_controller_software | 6.1.0.7 |
| ibm | san_volume_controller_software | 6.3.0.7 |
| ibm | storwize_v5000_software | 7.1.0.3 |
| ibm | storwize_v3700_software | 6.4.1.6 |
| ibm | san_volume_controller_software | 6.1.0.8 |
| ibm | storwize_v3500_software | 7.1.0.5 |
| ibm | san_volume_controller_software | 7.2.0.2 |
| ibm | storwize_v7000_software | 6.3.0.1 |
| ibm | san_volume_controller_software | 6.3.0.6 |
| ibm | flex_system_v7000_software | 7.1.0.7 |
| ibm | san_volume_controller_software | 6.4.0.0 |
| ibm | storwize_v7000 | - |
| ibm | storwize_v7000_software | 6.3.0.0 |
| ibm | storwize_v7000_software | 7.1.0.7 |
| ibm | storwize_v7000_software | 6.3.0.3 |
| ibm | storwize_v7000_software | 6.4.0.2 |
| ibm | san_volume_controller_software | 7.1.0.7 |
| ibm | storwize_v7000_software | 7.2.0.0 |
| ibm | storwize_v5000 | - |
| ibm | storwize_v7000_software | 6.4.0.3 |
| ibm | san_volume_controller_software | 7.2.0.0 |
| ibm | flex_system_v7000_software | 7.1.0.2 |
| ibm | storwize_v3700_software | 6.4.1.2 |
| ibm | flex_system_v7000_software | 7.1.0.6 |
| ibm | storwize_v3500_software | 6.4.1.5 |
| ibm | san_volume_controller_software | 6.3.0.0 |
| ibm | storwize_v7000_software | 6.3.0.5 |
| ibm | storwize_v3500_software | 7.2.0.1 |
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integrated_management_module_firmware | * |
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integrated_management_module_firmware | 3.50 |
| ibm | integrated_management_module_firmware | 3.67 |
| ibm | integrated_management_module_firmware | 3.65 |
| ibm | integrated_management_module_firmware | 3.55 |
| ibm | integrated_management_module_firmware | 3.56 |
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_hardware_management_console | 7r7.2.0 |
| ibm | power_hardware_management_console | 7r7.6.0 |
| ibm | power_hardware_management_console | 7r7.8.0 |
| ibm | power_hardware_management_console | 7r7.5.0 |
| ibm | power_hardware_management_console | 7r7.4.0 |
| ibm | power_hardware_management_console | 7r7.1.0 |
| ibm | power_hardware_management_console | 7r7.3.5 |
| ibm | power_hardware_management_console | 7r7.7.0 |
| ibm | power_hardware_management_console | 7r7.3.0 |
Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.8.1 |
Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.8.1 |
The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.8.1 |
The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.8.1 |
IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | worklight | 5.0.6.1 |
| ibm | mobile_foundation | 5.0.5.0 |
| ibm | worklight | 5.0.0.1 |
| ibm | worklight | 6.0.0.1 |
| ibm | worklight | 5.0.0.0 |
| ibm | worklight | 6.0.0.2 |
| ibm | mobile_foundation | 5.0.5.1 |
| ibm | worklight | 5.0.5.1 |
| ibm | mobile_foundation | 5.0.0.1 |
| ibm | mobile_foundation | 6.1.0.0 |
| ibm | worklight | 5.0.0.2 |
| ibm | worklight | 5.0.6.0 |
| ibm | worklight | 6.1.0.1 |
| ibm | mobile_foundation | 5.0.6.1 |
| ibm | mobile_foundation | 5.0.0.0 |
| ibm | mobile_foundation | 6.0.0.0 |
| ibm | worklight | 5.0.6.2 |
| ibm | mobile_foundation | 5.0.0.2 |
| ibm | mobile_foundation | 5.0.0.3 |
| ibm | worklight | 5.0.5.0 |
| ibm | worklight | 6.0.0.0 |
| ibm | mobile_foundation | 6.0.0.1 |
| ibm | worklight | 6.1.0.0 |
| ibm | mobile_foundation | 6.0.0.2 |
| ibm | mobile_foundation | 6.1.0.1 |
| ibm | worklight | 5.0.0.3 |
| ibm | mobile_foundation | 5.0.6.2 |
| ibm | mobile_foundation | 5.0.6.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.1.6 |
| ibm | atlas_ediscovery_process_management | * |
| ibm | disposal_and_governance_management_for_it | * |
| ibm | disposal_and_governance_management_for_it | 6.0.1.6 |
| ibm | global_retention_policy_and_schedule_management | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.6 |
| ibm | global_retention_policy_and_schedule_management | * |
| ibm | disposal_and_governance_management_for_it | 6.0.2 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.5 |
| ibm | atlas_suite | - |
| ibm | atlas_ediscovery_process_management | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.5 |
| ibm | atlas_ediscovery_process_management | 6.0.1.5 |
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.5.1.2 |
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_notes | 8.5.1.5 |
| ibm | lotus_notes | 8.5.2.0 |
| ibm | lotus_domino | 8.5.3.5 |
| ibm | lotus_domino | 8.5.2.2 |
| ibm | lotus_domino | 8.5.1.1 |
| ibm | lotus_notes | 8.5.1.4 |
| ibm | lotus_domino | 8.5.3.4 |
| ibm | lotus_notes | 8.5.3.5 |
| ibm | lotus_domino | 8.5.1.4 |
| ibm | lotus_notes | 8.5.3.2 |
| ibm | lotus_notes | 8.5.2.1 |
| ibm | lotus_domino | 8.5.2.0 |
| ibm | lotus_domino | 8.5.3.1 |
| ibm | lotus_domino | 8.5.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.1.0 |
| ibm | lotus_domino | 8.5.1 |
| ibm | lotus_notes | 8.5.0.1 |
| ibm | lotus_domino | 9.0.0.0 |
| ibm | lotus_domino | 8.5.3.3 |
| ibm | lotus_domino | 8.5.1.2 |
| ibm | lotus_notes | 9.0.1.0 |
| ibm | lotus_domino | 8.5.3.6 |
| ibm | lotus_domino | 8.5.3.2 |
| ibm | lotus_notes | 8.5.3.6 |
| ibm | lotus_domino | 8.5.1.3 |
| ibm | lotus_notes | 8.5.3 |
| ibm | lotus_domino | 8.5.2.4 |
| ibm | lotus_domino | 8.5.1.5 |
| ibm | lotus_notes | 8.5.1.1 |
| ibm | lotus_notes | 8.5.2.2 |
| ibm | lotus_notes | 9.0.0.0 |
| ibm | lotus_notes | 8.5.3.4 |
| ibm | lotus_domino | 8.5.2.3 |
| ibm | lotus_notes | 8.5.1 |
| ibm | lotus_notes | 8.5.1.2 |
| ibm | lotus_notes | 8.5.1.3 |
| ibm | lotus_domino | 8.5.0.1 |
| ibm | lotus_notes | 8.5.0.0 |
| ibm | lotus_domino | 8.5.2.1 |
| ibm | lotus_notes | 8.5.2.3 |
| ibm | lotus_notes | 8.5.3.3 |
| ibm | lotus_notes | 8.5.1.0 |
| ibm | lotus_notes | 8.5.3.1 |
| ibm | lotus_notes | 8.5 |
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_credit_limits | 4.7.0 |
| ibm | algorithmics | - |
| ibm | algo_credit_limits | 4.5.0 |
Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_samplepower | 3.0.1.0 |
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection mechanisms via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager | 1.2.0 |
| ibm | flex_system_manager | 1.3.0 |
| ibm | flex_system_manager | 1.2.1 |
| ibm | flex_system_manager | 1.3.1 |
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.1.1 |
| ibm | aix | 7.1.2 |
Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connections integration in IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attackers to execute arbitrary code via a crafted file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8 |
| ibm | security_appscan | 8.6 |
| ibm | security_appscan | 8.5 |
| ibm | security_appscan | 8.0 |
| ibm | security_appscan | 7.9 |
| ibm | security_appscan | 8.7 |
IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 2.1.1.0 |
| ibm | infosphere_biginsights | 2.0.0.0 |
| ibm | infosphere_biginsights | 2.1.0.0 |
| ibm | infosphere_biginsights | 2.1.2.0 |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.0.1.0 |
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 10.1.0.2 |
The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments via REST API calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 7.5.0.0 |
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.1.4 |
| ibm | rational_license_key_server | 8.1.4.3 |
| ibm | rational_license_key_server | 8.1.4.2 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 7.1.0.3 |
| ibm | websphere_mq | 7.1.0.1 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.1.0.4 |
| ibm | websphere_mq | 7.1.0.2 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.1 |
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.3.6 |
| ibm | lotus_domino | 9.0.1.0 |
| ibm | lotus_inotes | 9.0.1.0 |
| ibm | lotus_domino | 8.5.3.6 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management for IT and Maximo Service Desk allows remote authenticated users to inject arbitrary web script or HTML via the Query Description Field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_for_life_sciences | * |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | * |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_nuclear_power | * |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_for_utilities | * |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | * |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_service_desk | * |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | * |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | * |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | * |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_transportation | * |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via (1) the KPI display name field or (2) a portlet field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_for_life_sciences | * |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | * |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_nuclear_power | * |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_for_utilities | * |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | * |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_service_desk | * |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | * |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | * |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | * |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_transportation | * |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytic_server | 1.0.1.0 |
| ibm | spss_analytic_server | 1.0.0.0 |
The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | messagesight | - |
| ibm | messagesight_jms_client | 1.0.0.0 |
| ibm | messagesight_jms_client | 1.1.0.0 |
| ibm | messagesight_jms_client | 1.0.0.1 |
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | messagesight | - |
| ibm | messagesight_jms_client | 1.0.0.0 |
| ibm | messagesight_jms_client | 1.1.0.0 |
| ibm | messagesight_jms_client | 1.0.0.1 |
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | messagesight | - |
| ibm | messagesight_jms_client | 1.0.0.0 |
| ibm | messagesight_jms_client | 1.1.0.0 |
| ibm | messagesight_jms_client | 1.0.0.1 |
IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | messagesight | - |
| ibm | messagesight_jms_client | 1.0.0.0 |
| ibm | messagesight_jms_client | 1.1.0.0 |
| ibm | messagesight_jms_client | 1.0.0.1 |
Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_control_center | 5.4.0.1 |
| ibm | sterling_control_center | 5.4.1.0 |
| ibm | sterling_control_center | 5.4.0 |
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 1.0.2.0 |
| ibm | connections | 2.0.0.0 |
| ibm | connections | 2.0.1.0 |
| ibm | connections | 3.0.0.0 |
| ibm | connections | 2.5.0.1 |
| ibm | connections | 1.0.0.0 |
| ibm | connections | 2.0.1.1 |
| ibm | connections | * |
| ibm | connections | 1.0.1.0 |
| ibm | connections | 2.5.0.0 |
| ibm | connections | 2.5.0.3 |
| ibm | connections | 3.0.1.0 |
| ibm | connections | 2.5.0.2 |
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.1.0 |
Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integrations components in IBM Rational ClearCase 7.1.0.x, 7.1.1.x, 7.1.2 through 7.1.2.13, 8.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92263.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | * |
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_order_management | 8.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.0 |
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server_metadata_workbench | 8.7.0 |
| ibm | infosphere_information_server_metadata_workbench | 8.1.1 |
| ibm | infosphere_information_server_metadata_workbench | 9.1.0.1 |
| ibm | infosphere_information_server_metadata_workbench | 8.5.0.3 |
| ibm | infosphere_information_server_metadata_workbench | 8.5.0 |
| ibm | infosphere_information_server_metadata_workbench | 8.7.0.1 |
| ibm | infosphere_information_server_metadata_workbench | 8.1.0 |
| ibm | infosphere_information_server_metadata_workbench | 8.5.0.2 |
| ibm | infosphere_information_server_metadata_workbench | 8.1.0.2 |
| ibm | infosphere_information_server_metadata_workbench | 8.1.0.1 |
| ibm | infosphere_information_server_metadata_workbench | 8.7.0.2 |
| ibm | infosphere_information_server_metadata_workbench | 9.1.0 |
| ibm | infosphere_information_server_metadata_workbench | 8.5.0.1 |
Unspecified vulnerability in IBM Smart Analytics System 7700 before FP 2.1.3.0 and 7710 before FP 2.1.3.0 allows local users to gain privileges via vectors related to events.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | smart_analytics_system_7700 | 2.0.2.0 |
| ibm | smart_analytics_system_7710 | 2.0.3.0 |
| ibm | smart_analytics_system_7700 | 1.3.0.1 |
| ibm | smart_analytics_system_7700 | * |
| ibm | smart_analytics_system_7710 | 1.2.0 |
| ibm | smart_analytics_system_7710 | 1.2.0.100 |
| ibm | smart_analytics_system_7700 | 2.0.4.0 |
| ibm | smart_analytics_system_7700 | 1.2.2.0 |
| ibm | smart_analytics_system_7700 | 2.0.1.0 |
| ibm | smart_analytics_system_7700 | 1.3.0.0 |
| ibm | smart_analytics_system_7710 | 2.0.0.100 |
| ibm | smart_analytics_system_7710 | 2.0.2.0 |
| ibm | smart_analytics_system_7700 | 2.0.0 |
| ibm | smart_analytics_system_7710 | 1.3.0.1 |
| ibm | smart_analytics_system_7710 | 2.0.1.0 |
| ibm | smart_analytics_system_7700 | 2.1.1.0 |
| ibm | smart_analytics_system_7700 | 2.0.0.100 |
| ibm | smart_analytics_system_7710 | 2.0.4.0 |
| ibm | smart_analytics_system_7700 | 2.0.3.0 |
| ibm | smart_analytics_system_7700 | 1.2.4.0 |
| ibm | smart_analytics_system_7700 | 1.2.0.100 |
| ibm | smart_analytics_system_7710 | 1.2.2.0 |
| ibm | smart_analytics_system_7710 | 2.0.0 |
| ibm | smart_analytics_system_7710 | 2.1.1.0 |
| ibm | smart_analytics_system_7710 | 1.2.4.0 |
| ibm | smart_analytics_system_7700 | 1.2.1.0 |
| ibm | smart_analytics_system_7710 | 1.3.0.0 |
| ibm | smart_analytics_system_7710 | 1.2.1.0 |
| ibm | smart_analytics_system_7700 | 1.2.0 |
| ibm | smart_analytics_system_7710 | * |
IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 8.6 |
| ibm | security_appscan_source | 8.7 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 9.0 |
| ibm | security_appscan_source | 8.0 |
| ibm | security_appscan_source | 8.8 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) REST API or (2) Self Service UI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_service_automation_manager | 7.2.2.2 |
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/omnibus | 7.4.0 |
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0941.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/omnibus | 7.4.0 |
IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 through Feature Pack 7 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a malformed id parameter in a request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operational_decision_manager | 8.0 |
| ibm | operational_decision_manager | 8.5 |
| ibm | operational_decision_manager | 7.5 |
Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operational_decision_manager | 8.0 |
| ibm | operational_decision_manager | 8.5 |
| ibm | operational_decision_manager | 7.5 |
The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operational_decision_manager | 8.0 |
| ibm | operational_decision_manager | 8.5 |
| ibm | operational_decision_manager | 7.5 |
Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 4.0.6 |
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.3 |
| ibm | rhapsody_design_manager | 3.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rhapsody_design_manager | 3.0.0 |
| ibm | rhapsody_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rhapsody_design_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rhapsody_design_manager | 4.0.2 |
| ibm | rhapsody_design_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rhapsody_design_manager | 3.0.0.1 |
| ibm | rhapsody_design_manager | 4.0.0 |
| ibm | rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | * |
Cross-site scripting (XSS) vulnerability in FilterForm.jsp in IBM WebSphere Portal 7.0 before 7.0.0.2 CF28 and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Social Rendering in Connections integration is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH session from a deployed virtual machine.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | pureapplication_system | 1.1.0.2 |
| ibm | pureapplication_system | 1.0.0.0 |
| ibm | pureapplication_system | 1.1.0.3 |
| ibm | pureapplication_system | 1.0.0.1 |
| ibm | pureapplication_system | 1.0.0.4 |
| ibm | pureapplication_system | 1.1.0.0 |
| ibm | pureapplication_system | 1.1.0.4 |
| ibm | pureapplication_system | 1.0.0.2 |
| ibm | pureapplication_system | 1.0.0.3 |
| ibm | pureapplication_system | 1.1.0.1 |
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_identity_manager | 5.1.0.5 |
| ibm | tivoli_identity_manager | 5.0.0.11 |
| ibm | tivoli_identity_manager | 5.1.0.11 |
| ibm | tivoli_identity_manager | 5.1.0.6 |
| ibm | security_identity_manager | 6.0.0 |
| ibm | tivoli_identity_manager | 5.0.0.12 |
| ibm | tivoli_identity_manager | 5.1.0 |
| ibm | tivoli_identity_manager | 5.1.0.12 |
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | tivoli_identity_manager | 5.1.0.10 |
| ibm | tivoli_identity_manager | 5.1.0.9 |
| ibm | tivoli_identity_manager | 5.1.0.3 |
| ibm | tivoli_identity_manager | 5.0.0.6 |
| ibm | tivoli_identity_manager | 5.1.0.8 |
| ibm | tivoli_identity_manager | 5.1.0.13 |
| ibm | tivoli_identity_manager | 5.0.0.10 |
| ibm | tivoli_identity_manager | 5.0.0.13 |
| ibm | tivoli_identity_manager | 5.1.0.14 |
| ibm | tivoli_identity_manager | 5.1.0.7 |
| ibm | tivoli_identity_manager | 5.0.0 |
| ibm | tivoli_identity_manager | 5.1.0.4 |
| ibm | tivoli_identity_manager | 5.0.0.14 |
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_software | 7.0 |
| ibm | security_access_manager_for_web_software | 8.0 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.1.0.47 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 6.0.2.43 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.2.1 |
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.2 |
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.0 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.3 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL for an MHTML document.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.2 |
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.0 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.3 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
| oracle | javafx | 2.2.51 |
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | jre | 1.7.0 |
| ibm | forms_viewer | * |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| oracle | jre | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| oracle | jre | 1.8.0 |
| oracle | javafx | 2.2.51 |
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.5.0 |
| canonical | ubuntu_linux | 13.10 |
| canonical | ubuntu_linux | 12.04 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.5.0 |
| canonical | ubuntu_linux | 12.10 |
| oracle | jre | 1.8.0 |
| debian | debian_linux | 7.0 |
| oracle | jrockit | r27.8.1 |
| canonical | ubuntu_linux | 14.04 |
| ibm | forms_viewer | * |
| canonical | ubuntu_linux | 10.04 |
| juniper | junos_space | * |
| oracle | jrockit | r28.3.1 |
| oracle | jre | 1.6.0 |
| debian | debian_linux | 6.0 |
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | jre | 1.7.0 |
| ibm | forms_viewer | * |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jre | 1.8.0 |
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 10.1 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 8.0.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 6.2.0 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.4 |
IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 6.1.0.1 |
Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.3.0 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to a (1) custom JSP or (2) custom renderer.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 4.5 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.3.0 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 5.0 |
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime_proxy_server_and_web_client | 9.0.0.1 |
| ibm | sametime_proxy_server_and_web_client | 9.0.0.0 |
IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of service (reboot) via a flood of IP packets.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sas_raid_module_firmware | * |
| ibm | sas_connectivity_module_firmware | * |
IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sas_raid_module_firmware | * |
| ibm | sas_connectivity_module_firmware | * |
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_integrated_portal | 2.2 |
| ibm | embedded_websphere_application_server | 7.0 |
| ibm | tivoli_integrated_portal | 2.1 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via unspecified input to a .jsp file under webclient/utility/.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_for_life_sciences | * |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | * |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_nuclear_power | * |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_for_utilities | * |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | * |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_service_desk | * |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | * |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | * |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | tivoli_it_asset_management_for_it | * |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management_essentials | 6.2.0.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_transportation | * |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_industry_solutions | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | smartcloud_control_desk | 7.5.1.3 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.6 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_industry_solutions | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_industry_solutions | 7.5.0.1 |
| ibm | maximo_industry_solutions | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_industry_solutions | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_industry_solutions | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_industry_solutions | 7.5.0.5 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_service_manager | 4.2 |
| ibm | tivoli_business_service_manager | 4.2.1 |
Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/omnibus | 7.3.1.0 |
| ibm | tivoli_netcool/omnibus | 7.3.0 |
| ibm | tivoli_netcool/omnibus | 7.3.1.3 |
| ibm | tivoli_netcool/omnibus | 7.3.0.4 |
| ibm | tivoli_netcool/omnibus | 7.3.0.1 |
| ibm | tivoli_netcool/omnibus | 7.4.0 |
| ibm | tivoli_netcool/omnibus | 7.3.0.2 |
| ibm | tivoli_netcool/omnibus | 7.4.0.1 |
| ibm | tivoli_netcool/omnibus | 7.3.0.5 |
| ibm | tivoli_netcool/omnibus | 7.3.1.2 |
| ibm | tivoli_netcool/omnibus | 7.3.1.1 |
| ibm | tivoli_netcool/omnibus | 7.3.1.6 |
| ibm | tivoli_netcool/omnibus | 7.4.0.2 |
| ibm | tivoli_netcool/omnibus | 7.3.0.3 |
| ibm | tivoli_netcool/omnibus | 7.3.1.4 |
| ibm | tivoli_netcool/omnibus | 7.3.1.5 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing_portfolio | 9.5.1.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.0.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.1 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.1 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.1 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.2 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 9.5.0.6 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 10.0.2.0 |
| ibm | emptoris_spend_analysis | 10.0.1.2 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.0.2.2 |
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 10.0.1.1 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attackers to bypass intended restrictions on topology access, and obtain sensitive information, via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 3.0.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_engineering_lifecycle_manager | 4.03 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 4.05 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.04 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_modeler | 16.0.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2; Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4; and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_spend_analysis | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.1 |
| ibm | emptoris_spend_analysis | 10.0.1.2 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_spend_analysis | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.2 |
| ibm | emptoris_spend_analysis | 10.0.2.0 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.1 |
| ibm | emptoris_spend_analysis | 10.0.1.1 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.3 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.0.2.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_contract_management | 9.5.0.6 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 9.5.0.6 |
IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which allows remote authenticated users to cause a denial of service (storage overlay) by using a 3270 emulator to send an invalid 3270 data stream.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cics_transaction_server | 3.1 |
| ibm | cics_transaction_server | 3.2 |
| ibm | cics_transaction_server | 5.1 |
| ibm | cics_transaction_server | - |
| ibm | cics_transaction_server | 4.1 |
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service account.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000_software | 1.4.0.4 |
| ibm | storwize_unified_v7000 | - |
| ibm | storwize_unified_v7000_software | 1.3.0.0 |
| ibm | storwize_unified_v7000_software | 1.4.3.2 |
| ibm | storwize_unified_v7000_software | 1.3.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.2 |
| ibm | storwize_unified_v7000_software | 1.4.0.5 |
| ibm | storwize_unified_v7000_software | 1.4.2.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.3 |
| ibm | storwize_unified_v7000_software | 1.4.2.1 |
| ibm | storwize_unified_v7000_software | 1.4.3.1 |
| ibm | storwize_unified_v7000_software | 1.4.1.1 |
| ibm | storwize_unified_v7000_software | 1.4.0.0 |
| ibm | storwize_unified_v7000_software | 1.4.1.0 |
| ibm | storwize_unified_v7000_software | 1.4.3.0 |
| ibm | storwize_unified_v7000_software | 1.4.0.1 |
IBM Scale Out Network Attached Storage (SONAS) 1.3.x and 1.4.x before 1.4.3.3 places an administrative password in the shell history upon use of the -p option to chuser, which allows local users to obtain sensitive information by leveraging root access.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | scale_out_network_attached_storage | * |
Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges by leveraging the TSSC service-user role to enter a crafted SSH command.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_storage_virtualization_engine_ts7700 | - |
| ibm | system_storage_virtualization_engine_ts7700_firmware | - |
IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 3.0.1.6 |
The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain credential information via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_composite_application_manager_for_transactions | 7.2.0.0 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.2.0.2 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.1.0.0 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.1.0.2 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.1.0.3 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.1.0.4 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.2.0.1 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.1.0.1 |
| ibm | tivoli_composite_application_manager_for_transactions | 7.3.0.0 |
The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that lack NIST SP 800-131A compliance.
CVSS 2.0
Severity: LOW
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_appliance | 8.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_software | 7.0 |
| ibm | security_access_manager_for_web_software | 8.0 |
| ibm | security_access_manager_for_mobile_software | 8.0 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_mobile_appliance | 8.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal_unified_task_list_portlet | 6.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal_unified_task_list_portlet | 6.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal_unified_task_list_portlet | 6.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal_unified_task_list_portlet | 6.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
Unspecified vulnerability in the Administrative Console on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance | - |
Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance | - |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 10.0.2.0 |
| ibm | emptoris_spend_analysis | 10.0.1.2 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.0.2.2 |
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 10.0.1.1 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
Unspecified vulnerability in IBM Security QRadar SIEM 7.1 MR2 and 7.2 MR2 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.2 |
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.0 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.3 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_collaboration_server | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_collaboration_server | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_collaboration_server | 11.0 |
Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| ibm | java | 5.0.15.0 |
| ibm | java | 5.0.16.1 |
| ibm | java | 6.0.9.0 |
| ibm | java | 5.0.16.0 |
| ibm | java | 5.0.16.2 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 6.0.8.1 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.0.0 |
| ibm | java | 6.0.11.0 |
| ibm | java | 5.0.12.2 |
| ibm | java | 5.0.11.2 |
| ibm | java | 5.0.14.0 |
| ibm | java | 5.0.16.3 |
| ibm | java | 7.0.4.0 |
| ibm | java | 6.0.1.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.14.0 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.11.1 |
| ibm | java | 5.0.13.0 |
| ibm | java | 7.0.5.0 |
| ibm | java | 6.0.10.0 |
| ibm | java | 6.0.8.0 |
| ibm | java | 6.0.9.2 |
| ibm | java | 5.0.12.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| ibm | java | 6.0.2.0 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.12.0 |
| ibm | java | 6.0.13.0 |
| ibm | java | 6.0.3.0 |
| ibm | java | 6.0.9.1 |
IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | 9.1 |
IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 5.0.0.0 |
| ibm | java | 5.0.12.5 |
| ibm | java | 6.0.13.2 |
| ibm | java | 5.0.12.4 |
| ibm | java | 5.0.15.0 |
| ibm | java | 5.0.16.1 |
| ibm | java | 6.0.9.0 |
| ibm | java | 5.0.16.0 |
| ibm | java | 5.0.16.2 |
| ibm | java | 5.0.12.1 |
| ibm | java | 6.0.0.0 |
| ibm | java | 6.0.5.0 |
| ibm | java | 6.0.8.1 |
| ibm | java | 7.0.4.1 |
| ibm | java | 7.0.0.0 |
| ibm | java | 6.0.11.0 |
| ibm | java | 5.0.12.2 |
| ibm | java | 5.0.11.2 |
| ibm | java | 5.0.14.0 |
| ibm | java | 5.0.16.3 |
| ibm | java | 7.0.4.0 |
| ibm | java | 6.0.1.0 |
| ibm | java | 7.0.4.2 |
| ibm | java | 6.0.14.0 |
| ibm | java | 6.0.10.1 |
| ibm | java | 5.0.11.1 |
| ibm | java | 5.0.13.0 |
| ibm | java | 7.0.5.0 |
| ibm | java | 6.0.10.0 |
| ibm | java | 6.0.8.0 |
| ibm | java | 6.0.9.2 |
| ibm | java | 5.0.12.0 |
| ibm | java | 7.0.1.0 |
| ibm | java | 5.0.12.3 |
| ibm | java | 6.0.6.0 |
| ibm | java | 5.0.11.0 |
| ibm | java | 7.0.2.0 |
| ibm | java | 6.0.2.0 |
| ibm | java | 6.0.4.0 |
| ibm | java | 7.0.3.0 |
| ibm | java | 6.0.7.0 |
| ibm | java | 6.0.13.1 |
| ibm | java | 6.0.12.0 |
| ibm | java | 6.0.13.0 |
| ibm | java | 6.0.3.0 |
| ibm | java | 6.0.9.1 |
Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.5.5 |
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, and 9.0 through 9.0.0.1 allows local users to gain privileges by executing a crafted service.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 8.6 |
| ibm | security_appscan_source | 8.6.0.1 |
| ibm | security_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 8.6.0.2 |
| ibm | security_appscan_source | 8.7.0.1 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 8.0 |
| ibm | security_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 9.0 |
| ibm | security_appscan_source | 8.7.0.0 |
| ibm | security_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 8.8 |
| ibm | security_appscan_source | 9.0.0.1 |
Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_software | 7.0 |
| ibm | security_access_manager_for_web_software | 8.0 |
| ibm | security_access_manager_for_mobile_software | 8.0 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
| ibm | security_access_manager_for_mobile_appliance | 8.0 |
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.2.1.8 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.2.5 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.1.0 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2 |
| ibm | websphere_application_server | 7.2.0.3 |
| ibm | websphere_application_server | 7.2.0.2 |
| ibm | websphere_application_server | 7.2.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_application_server | 7.2.0.1 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere_application_server | 7.2.0.5 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000 | - |
| ibm | storwize_v7000_unified_software | 1.3.2.0 |
| ibm | storwize_v7000_unified_software | 1.3.0.0 |
| ibm | storwize_v7000_unified_software | 1.4.3.0 |
| ibm | storwize_v7000_unified_software | 1.3.2.3 |
| ibm | storwize_v7000_unified_software | 1.4.1.1 |
| ibm | storwize_v7000_unified_software | 1.4.0.0 |
| ibm | storwize_v7000_unified_software | 1.4.1.0 |
| ibm | storwize_v7000_unified_software | 1.4.2.0 |
| ibm | storwize_v7000_unified_software | 1.4.3.3 |
| ibm | storwize_v7000_unified_software | 1.4.0.4 |
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.1.4 |
| ibm | rational_license_key_server | 8.1.4.3 |
| ibm | rational_license_key_server | 8.1.4.2 |
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | global_console_manager_32_firmware | * |
| ibm | global_console_manager_16_firmware | * |
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | global_console_manager_32_firmware | * |
| ibm | global_console_manager_16_firmware | * |
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended write-access restrictions on calendar entries via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 6.2.6 |
| ibm | maximo_asset_management | 6.2.7 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 6.2.6.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 6.2.3 |
| ibm | maximo_asset_management | 6.2.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.0 |
| ibm | maximo_asset_management | 6.2.8 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | smartcloud_control_desk | 7.0 |
| ibm | maximo_asset_management | 6.2.4 |
| ibm | tivoli_asset_management_for_it | 6.2 |
| ibm | maximo_asset_management | 6.2.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 6.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_asset_management | 6.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 6.2 |
| ibm | maximo_asset_management | 6.2.2 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | global_console_manager_32_firmware | * |
| ibm | global_console_manager_16_firmware | * |
Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_real_time | 3.0 |
| ibm | lotus_notes | 8.5.3.0 |
| ibm | lotus_domino | 8.5.3.0 |
| ibm | lotus_domino | 9.0.1.0 |
| ibm | lotus_notes | 9.0.1.0 |
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime_meeting_server | 8.5.1 |
The RDS Java Client library in IBM Rational Directory Server (RDS) 5.1.1.x before 5.1.1.2 iFix004 and 5.2.x before 5.2.1 iFix003, and Rational Directory Administrator (RDA) 6.0 before iFix002, includes the cleartext root password, which allows local users to obtain sensitive information by reading a library file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_directory_server | 5.2 |
| ibm | rational_directory_server | 5.2.0.2 |
| ibm | rational_directory_server | 5.1.1.2 |
| ibm | rational_directory_administrator | 6.0 |
| ibm | rational_directory_administrator | 6.0.0.1 |
| ibm | rational_directory_server | 5.2.1 |
| ibm | rational_directory_server | 5.1.1.1 |
| ibm | rational_directory_server | 5.2.0.1 |
| ibm | rational_directory_server | 5.1.1 |
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.0 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.05 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.04 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_engineering_lifecycle_manager | 4.06 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.03 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.0.0 |
| ibm | powervc | 1.2.1.1 |
| ibm | powervc | 1.2.1.0 |
Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2 | 10.1.0.2 |
The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.5.0.6 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.5.0.5 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.5.0.10 |
| ibm | db2 | 9.5.0.1 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 9.5.0.4 |
| ibm | db2 | 9.5.0.8 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.5.0.7 |
| ibm | db2 | 9.5.0.3 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2 | 9.5.0.9 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.5.0.2 |
| ibm | db2 | 9.5 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2 | 9.8.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | * |
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | systems_director | 6.3.2.0 |
| ibm | systems_director | 6.3.1.1 |
| ibm | systems_director | 6.3.3.0 |
| ibm | systems_director | 6.3.5.0 |
| ibm | systems_director | 6.3.0.0 |
| ibm | systems_director | 6.3.1.0 |
| ibm | systems_director | 6.3.2.1 |
| ibm | systems_director | 6.3.3.1 |
| ibm | systems_director | 6.3.2.2 |
The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a delay after a failed authentication attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protection mechanism, which allows remote attackers to bypass authentication and read files via the Help Server Administration feature.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 7.1.0.1 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.1.9 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.1.1 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 7.1.1.4 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 7.1.1.6 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 7.1.0.2 |
| ibm | rational_clearcase | 7.1.1.5 |
| ibm | rational_clearcase | 7.1.1.7 |
| ibm | rational_clearcase | 7.1.1.8 |
| ibm | rational_clearcase | 7.1.1.2 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 8.0 |
| ibm | rational_clearcase | 7.1.1 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 7.1 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.1.3 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 3.4 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N | 1.6 | 1.4 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.4 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N | 1.6 | 1.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,CWE-329,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| openssl | openssl | 0.9.8d |
| netbsd | netbsd | 6.1.1 |
| netbsd | netbsd | 5.2.1 |
| netbsd | netbsd | 6.0.3 |
| openssl | openssl | 1.0.1e |
| redhat | enterprise_linux_workstation | 7.0 |
| openssl | openssl | 1.0.1g |
| netbsd | netbsd | 6.0.2 |
| openssl | openssl | 1.0.1h |
| debian | debian_linux | 7.0 |
| netbsd | netbsd | 6.0.6 |
| redhat | enterprise_linux_workstation | 6.0 |
| openssl | openssl | 1.0.1a |
| novell | suse_linux_enterprise_desktop | 12.0 |
| netbsd | netbsd | 6.1.4 |
| netbsd | netbsd | 5.2.2 |
| openssl | openssl | 0.9.8u |
| novell | suse_linux_enterprise_desktop | 10.0 |
| netbsd | netbsd | 6.1.5 |
| ibm | vios | 2.2.1.0 |
| netbsd | netbsd | 6.1.2 |
| openssl | openssl | 1.0.1i |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | vios | 2.2.1.4 |
| openssl | openssl | 0.9.8y |
| novell | suse_linux_enterprise_server | 12.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| fedoraproject | fedora | 19 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| fedoraproject | fedora | 20 |
| redhat | enterprise_linux_server_supplementary | 5.0 |
| mageia | mageia | 3.0 |
| openssl | openssl | 0.9.8g |
| openssl | openssl | 0.9.8r |
| openssl | openssl | 0.9.8b |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
| netbsd | netbsd | 5.1.4 |
| redhat | enterprise_linux | 5 |
| netbsd | netbsd | 6.1 |
| openssl | openssl | 1.0.1c |
| redhat | enterprise_linux_desktop_supplementary | 5.0 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.1 |
| openssl | openssl | 0.9.8f |
| openssl | openssl | 0.9.8x |
| ibm | vios | 2.2.2.4 |
| openssl | openssl | 1.0.0f |
| netbsd | netbsd | 6.0 |
| netbsd | netbsd | 5.1 |
| redhat | enterprise_linux_desktop | 7.0 |
| openssl | openssl | 1.0.0 |
| redhat | enterprise_linux_workstation_supplementary | 6.0 |
| openssl | openssl | 0.9.8e |
| opensuse | opensuse | 12.3 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.1.1 |
| openssl | openssl | 0.9.8c |
| openssl | openssl | 1.0.0m |
| ibm | vios | 2.2.3.3 |
| openssl | openssl | 0.9.8n |
| openssl | openssl | 0.9.8a |
| netbsd | netbsd | 6.1.3 |
| openssl | openssl | 1.0.0k |
| netbsd | netbsd | 5.2 |
| netbsd | netbsd | 6.0.4 |
| netbsd | netbsd | 5.1.1 |
| openssl | openssl | 1.0.0h |
| openssl | openssl | 0.9.8s |
| openssl | openssl | 1.0.0n |
| openssl | openssl | 1.0.1 |
| openssl | openssl | 0.9.8q |
| ibm | vios | 2.2.2.2 |
| novell | suse_linux_enterprise_software_development_kit | 11.0 |
| redhat | enterprise_linux_desktop_supplementary | 6.0 |
| openssl | openssl | 0.9.8w |
| openssl | openssl | 0.9.8m |
| openssl | openssl | 0.9.8z |
| novell | suse_linux_enterprise_software_development_kit | 12.0 |
| openssl | openssl | 0.9.8p |
| openssl | openssl | 0.9.8l |
| openssl | openssl | 1.0.0i |
| ibm | vios | 2.2.1.6 |
| redhat | enterprise_linux_server | 7.0 |
| ibm | vios | 2.2.0.10 |
| oracle | database | 11.2.0.4 |
| ibm | vios | 2.2.1.9 |
| fedoraproject | fedora | 21 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| openssl | openssl | 1.0.1f |
| openssl | openssl | 1.0.0g |
| novell | suse_linux_enterprise_server | 11.0 |
| redhat | enterprise_linux_workstation_supplementary | 7.0 |
| openssl | openssl | 0.9.8za |
| openssl | openssl | 0.9.8k |
| ibm | vios | 2.2.1.7 |
| openssl | openssl | 1.0.1d |
| openssl | openssl | 0.9.8zb |
| debian | debian_linux | 8.0 |
| openssl | openssl | 0.9.8o |
| opensuse | opensuse | 13.1 |
| openssl | openssl | 0.9.8v |
| openssl | openssl | 1.0.0e |
| redhat | enterprise_linux_server_supplementary | 6.0 |
| openssl | openssl | 0.9.8t |
| ibm | vios | 2.2.2.5 |
| redhat | enterprise_linux_server | 6.0 |
| oracle | database | 12.1.0.2 |
| openssl | openssl | 1.0.0d |
| ibm | vios | 2.2.3.0 |
| redhat | enterprise_linux_server_supplementary | 7.0 |
| openssl | openssl | 0.9.8 |
| openssl | openssl | 1.0.0a |
| openssl | openssl | 1.0.0b |
| ibm | vios | 2.2.2.0 |
| netbsd | netbsd | 6.0.1 |
| openssl | openssl | 1.0.0j |
| apple | mac_os_x | * |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.5 |
| openssl | openssl | 0.9.8j |
| openssl | openssl | 1.0.0l |
| netbsd | netbsd | 5.1.2 |
| mageia | mageia | 4.0 |
| netbsd | netbsd | 6.0.5 |
| openssl | openssl | 0.9.8h |
| openssl | openssl | 1.0.0c |
| ibm | vios | 2.2.1.3 |
| openssl | openssl | 1.0.1b |
| novell | suse_linux_enterprise_desktop | 11.0 |
| netbsd | netbsd | 5.1.3 |
| novell | suse_linux_enterprise_desktop | 9.0 |
| openssl | openssl | 0.9.8i |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.1.0 |
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.2.1.8 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.2.5 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.1.0 |
IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the intranet network via a series of requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.0.1.0 |
Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.0.0 |
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 8.0.0.0 |
| ibm | sametime | 8.0.1.1 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 8.0.2.0 |
| ibm | sametime | 8.0.2.1 |
| ibm | sametime | 8.0.1.0 |
IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.0.0 |
IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Mobile 8.0.0.0, 8.0.0.1, and 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.0 |
IBM System Networking G8052, G8124, G8124-E, G8124-ER, G8264, G8316, and G8264-T switches before 7.9.10.0; EN4093, EN4093R, CN4093, SI4093, EN2092, and G8264CS switches before 7.8.6.0; Flex System Interconnect Fabric before 7.8.6.0; 1G L2-7 SLB switch for Bladecenter before 21.0.21.0; 10G VFSM for Bladecenter before 7.8.14.0; 1:10G switch for Bladecenter before 7.4.8.0; 1G switch for Bladecenter before 5.3.5.0; Server Connectivity Module before 1.1.3.4; System Networking RackSwitch G8332 before 7.7.17.0; and System Networking RackSwitch G8000 before 7.1.7.0 have hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bladecenter_10g_vfsm_firmware | * |
| ibm | server_connectivity_module_firmware | * |
| ibm | system_networking_rackswitch__g8124e | - |
| ibm | bladecenter_1g | - |
| ibm | system_networking_rackswitch__en4093_firmware | * |
| ibm | system_networking_rackswitch__si4093_firmware | * |
| ibm | system_networking_rackswitch__si4093 | - |
| ibm | server_connectivity_module | - |
| ibm | system_networking_rackswitch__g8052_firmware | * |
| ibm | system_networking_rackswitch__g8264 | - |
| ibm | system_networking_rackswitch__g8124_firmware | * |
| ibm | system_networking_rackswitch__g8264t | - |
| ibm | system_networking_rackswitch__g8332_firmware | * |
| ibm | system_networking_rackswitch__en4093r_firmware | * |
| ibm | system_networking_rackswitch__g8124 | - |
| ibm | bladecenter_1/10g_firmware | * |
| ibm | bladecenter_1g_l2-7_slb | - |
| ibm | system_networking_rackswitch__g8124e_firmware | * |
| ibm | system_networking_rackswitch__g8264cs_firmware | * |
| ibm | system_networking_rackswitch__en4093r | - |
| ibm | system_networking_rackswitch__g8332 | - |
| ibm | system_networking_rackswitch__cn4093_firmware | * |
| ibm | system_networking_rackswitch__g8264_firmware | * |
| ibm | system_networking_rackswitch__g8316_firmware | * |
| ibm | system_networking_rackswitch__g8124er | - |
| ibm | system_networking_rackswitch__en2092 | - |
| ibm | system_networking_rackswitch__g8316 | - |
| ibm | system_networking_rackswitch__g8124er_firmware | * |
| ibm | bladecenter_10g_vfsm | - |
| ibm | bladecenter_1g_firmware | * |
| ibm | bladecenter_1/10g | - |
| ibm | system_networking_rackswitch__g8052 | - |
| ibm | flex_system_interconnect_fabric | - |
| ibm | system_networking_rackswitch__en4093 | - |
| ibm | flex_system_interconnect_fabric_firmware | * |
| ibm | system_networking_rackswitch__g8264t_firmware | * |
| ibm | bladecenter_1g_l2-7_slb_firmware | * |
| ibm | system_networking_rackswitch__g8264cs | - |
| ibm | system_networking_rackswitch__en2092_firmware | * |
| ibm | system_networking_rackswitch__cn4093 | - |
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to hijack sessions via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.1.4 |
| ibm | rational_license_key_server | 8.1.4.3 |
| ibm | rational_license_key_server | 8.1.4.2 |
The Outlook Extension in IBM Content Collector 4.0.0.x before 4.0.0.0-ICC-OE-IF004 allows local users to bypass the intended Reviewer privilege requirement and read e-mail messages from an arbitrary mailbox by invoking the Search function.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_collector | 4.0.0.1 |
| ibm | content_collector | 4.0.0.0 |
| ibm | content_collector | 4.0.0.2 |
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2 |
| ibm | websphere_application_server | 7.2.0.3 |
| ibm | websphere_application_server | 7.2.0.2 |
| ibm | websphere_application_server | 7.2.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_application_server | 7.2.0.1 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere_application_server | 7.2.0.5 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 before 8.0.0.1 CF13, and 8.5.0 before CF01 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before 5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_foundation | 5.2.0 |
| ibm | filenet_content_manager | 5.2.0 |
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by reading an unspecified error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playback (RAP) file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | classic_meeting_server | 8.5.1.2 |
| ibm | classic_meeting_server | 8.5 |
| ibm | classic_meeting_server | 8.0.1 |
| ibm | classic_meeting_server | 8.0.2 |
| ibm | classic_meeting_server | 8.5.2.1 |
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | uefi | * |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.1.0.47 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 6.0.2.43 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authenticated users to cause a denial of service (queue-slot exhaustion) by leveraging PCF query privileges for a crafted query.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.12 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 7.1.0.5 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.1.0.4 |
| ibm | websphere_mq | 7.0.1.9 |
| ibm | websphere_mq | 7.1.0.2 |
| ibm | websphere_mq | 7.0.1.6 |
| ibm | websphere_mq | 7.1.0.3 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 7.1 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.10 |
| ibm | websphere_mq | 7.0.1.11 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.1.0.1 |
Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_family | 9.1.0 |
| ibm | license_metric_tool | 9.0 |
| ibm | endpoint_manager_family | 9.0.1 |
| ibm | license_metric_tool | 9.1.0.1 |
| ibm | license_metric_tool | 9.0.1 |
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.0 |
| ibm | license_metric_tool | 9.1.0.1 |
| ibm | license_metric_tool | 9.0.1 |
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_family | 9.1.0 |
| ibm | license_metric_tool | 9.0 |
| ibm | endpoint_manager_family | 9.0.1 |
| ibm | license_metric_tool | 9.1.0.1 |
| ibm | license_metric_tool | 9.0.1 |
The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API information via a network-tracing attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 3.0.0.1 |
| ibm | infosphere_biginsights | 2.1.2.0 |
| ibm | infosphere_biginsights | 3.0.0.0 |
IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management service. IBM X-Force ID: 95029.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 2.1.2 |
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote attackers to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
Cross-site scripting (XSS) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
Session fixation vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | initiate_master_data_service | 9.5 |
| ibm | initiate_master_data_service | 10.0 |
| ibm | initiate_master_data_service | 10.1 |
| ibm | initiate_master_data_service | 9.7 |
IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing_portfolio | 9.5.1.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.2 |
| ibm | emptoris_spend_analysis | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.0.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.1 |
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.1 |
| ibm | emptoris_spend_analysis | 10.0.1.1 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.3 |
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.1 |
| ibm | emptoris_spend_analysis | 10.0.1.2 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.0.2.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.2 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8.0.0.1 CF13, and 8.5.0 before CF02 allows remote authenticated users to cause a denial of service (disk consumption) by uploading large files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 6.0.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | * |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | * |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.5.5 |
IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 10.5.0.2 |
The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | * |
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | * |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.4 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.2 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.3 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.6 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0.1 |
Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for remote attackers to bypass intended Business Intelligence restrictions by leveraging access to authentication data that was captured before this logoff.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_mobile | 10.2.1 |
| ibm | cognos_mobile | 10.2.0 |
| ibm | cognos_mobile | 10.1.1 |
IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | san_volume_controller_software | 7.2.0.5 |
| ibm | san_volume_controller_software | 6.2.0.5 |
| ibm | san_volume_controller_software | 6.4.0.3 |
| ibm | san_volume_controller_software | 7.1.0.2 |
| ibm | san_volume_controller_software | 6.2.0.4 |
| ibm | san_volume_controller_software | 6.1.0.2 |
| ibm | san_volume_controller_software | 7.1.0.6 |
| ibm | san_volume_controller_software | 6.2.0.2 |
| ibm | san_volume_controller_software | 7.2.0.3 |
| ibm | storwize_v3500 | - |
| ibm | san_volume_controller_software | 7.1.0.0 |
| ibm | san_volume_controller_software | 6.4.0.2 |
| ibm | san_volume_controller_software | 6.4.1.1 |
| ibm | san_volume_controller_software | 7.1.0.1 |
| ibm | san_volume_controller_software | 7.1.0.3 |
| ibm | san_volume_controller_software | 6.3.0.4 |
| ibm | san_volume_controller_software | 7.2.0.7 |
| ibm | san_volume_controller_software | 6.1.0.9 |
| ibm | san_volume_controller_software | 6.2.0.3 |
| ibm | san_volume_controller_software | 6.1.0.5 |
| ibm | san_volume_controller_software | 6.1.0.1 |
| ibm | san_volume_controller_software | 7.2.0.1 |
| ibm | san_volume_controller_software | 6.2.0.0 |
| ibm | san_volume_controller_software | 6.4.1.5 |
| ibm | san_volume_controller_software | 6.4.1.8 |
| ibm | san_volume_controller_software | 6.1.0.3 |
| ibm | san_volume_controller_software | 6.2.0.6 |
| ibm | san_volume_controller_software | 6.1.0.4 |
| ibm | san_volume_controller_software | 6.1.0.7 |
| ibm | san_volume_controller_software | 7.2.0.6 |
| ibm | san_volume_controller_software | 6.2.0.1 |
| ibm | san_volume_controller_software | 6.3.0.7 |
| ibm | san_volume_controller_software | 6.4.1.6 |
| ibm | san_volume_controller_software | 6.3.0.3 |
| ibm | san_volume_controller_software | 6.3.0.2 |
| ibm | san_volume_controller_software | 6.1.0.8 |
| ibm | san_volume_controller_software | 7.2.0.4 |
| ibm | san_volume_controller_software | 7.2.0.2 |
| ibm | san_volume_controller_software | 6.4.0.4 |
| ibm | san_volume_controller_software | 6.3.0.6 |
| ibm | san_volume_controller_software | 6.4.0.0 |
| ibm | storwize_v7000 | - |
| ibm | san_volume_controller_software | 6.1.0.6 |
| ibm | san_volume_controller_software | 6.4.0.1 |
| ibm | san_volume_controller_software | 6.1.0.0 |
| ibm | san_volume_controller_software | 7.1.0.7 |
| ibm | san_volume_controller_software | 6.3.0.1 |
| ibm | san_volume_controller_software | 6.1.0.10 |
| ibm | san_volume_controller_software | 6.4.1.7 |
| ibm | storwize_v5000 | - |
| ibm | san_volume_controller_software | 6.4.1.2 |
| ibm | san_volume_controller_software | 7.2.0.0 |
| ibm | san_volume_controller_software | 6.3.0.5 |
| ibm | san_volume_controller_software | 6.4.1.3 |
| ibm | san_volume_controller_software | 6.3.0.0 |
| ibm | storwize_v3700 | - |
| ibm | san_volume_controller_software | 6.4.1.4 |
| ibm | san_volume_controller_software | 7.1.0.5 |
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 8.6 |
| ibm | security_appscan_source | 8.7 |
| ibm | security_appscan_source | 8.6.0.1 |
| ibm | security_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 8.6.0.2 |
| ibm | security_appscan_source | 8.7.0.1 |
| ibm | security_appscan_source | 8.5 |
| ibm | security_appscan_source | 8.0 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 9.0 |
| ibm | security_appscan_source | 8.7.0.0 |
| ibm | security_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 8.8 |
| ibm | security_appscan_source | 9.0.0.1 |
Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.5.4.1 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.4.3.4 |
| ibm | tivoli_storage_manager | 5.5.4 |
| ibm | tivoli_storage_manager | 6.2.4.7 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.2.4.4 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1.0 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 6.3.2.1 |
| ibm | tivoli_storage_manager | 5.5.4.2 |
| ibm | tivoli_storage_manager | 5.4.3.3 |
| ibm | tivoli_storage_manager | 6.2.0.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 5.4.3.6 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 6.3.0.1 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.5.4.3 |
| ibm | tivoli_storage_manager | 5.5.3 |
| ibm | tivoli_storage_manager | 6.3.0.0 |
| ibm | tivoli_storage_manager | 6.3.2 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
| ibm | tivoli_storage_manager | 6.2.1 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity expansion, which allows remote authenticated users to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: LOW
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remote attackers to hijack web sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | _ibm_rational_lifecycle_integration_adapter_for_windchill | 1.0.0 |
Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 6.0.2.19 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.0.2.7 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 6.0.2.25 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 6.0.2.9 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.0.2.41 |
| ibm | websphere_application_server | 6.1.0.47 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 6.0.2.13 |
| ibm | websphere_application_server | 6.0.1.11 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.0.2.15 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 6.0.2.4 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 6.0.2.6 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.0.2.37 |
| ibm | websphere_application_server | 6.0.2.24 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.0.2.5 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 6.0.1.1 |
| ibm | websphere_application_server | 6.0.2.1 |
| ibm | websphere_application_server | 6.0.1.5 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 6.0.0.1 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 6.0.0.2 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 6.0.2.39 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 6.0.2.33 |
| ibm | websphere_application_server | 6.0.1.2 |
| ibm | websphere_application_server | 6.0.1.17 |
| ibm | websphere_application_server | 6.0.1.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 6.0.2.31 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.0.2.35 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 6.0.2.22 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.0 |
| ibm | websphere_application_server | 6.0.1.3 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 6.0.2.43 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 6.0.2.2 |
| ibm | websphere_application_server | 6.0.2.11 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.0.1.15 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 6.0.2.30 |
| ibm | websphere_application_server | 6.0.2.32 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 6.0.2.23 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 6.0.1 |
| ibm | websphere_application_server | 6.0.1.7 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 6.0.2.17 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 6.0.2.3 |
| ibm | websphere_application_server | 6.0.2.29 |
| ibm | websphere_application_server | 6.0.1.9 |
| ibm | websphere_application_server | 6.0.2 |
| ibm | websphere_application_server | 6.0.2.28 |
| ibm | websphere_application_server | 6.0.2.27 |
| ibm | websphere_application_server | 6.0.0.3 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 7.0.0.4 |
The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.5.4.1 |
| ibm | tivoli_storage_manager | 5.2 |
| ibm | tivoli_storage_manager | 5.4.3.2 |
| ibm | tivoli_storage_manager | 5.1.6 |
| ibm | tivoli_storage_manager | 5.1.8 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.5.4 |
| ibm | tivoli_storage_manager | 6.2.4.7 |
| ibm | tivoli_storage_manager | 6.2.4.4 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.1.0 |
| ibm | tivoli_storage_manager | 6.3.2.1 |
| ibm | tivoli_storage_manager | 5.4.3.3 |
| ibm | tivoli_storage_manager | 6.3.0 |
| ibm | tivoli_storage_manager | 5.2.5.1 |
| ibm | tivoli_storage_manager | 6.0 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.2.1 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.3.0.0 |
| ibm | tivoli_storage_manager | 6.3.2 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 5.1.7 |
| ibm | tivoli_storage_manager | 5.4.2.3 |
| ibm | tivoli_storage_manager | 6.4.0 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 5.4.3.0 |
| ibm | tivoli_storage_manager | 5.2.2 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.1.9 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.1.5 |
| ibm | tivoli_storage_manager | 5.4.4.0 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.2.5.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 5.2.0 |
| ibm | tivoli_storage_manager | 7.1.0 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.1.1 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 5.2.8 |
| ibm | tivoli_storage_manager | 6.2.0.0 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.4.2.2 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 5.2.9 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.4 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 6.3.0.1 |
| ibm | tivoli_storage_manager | 5.2.4 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 5.1.10 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.5.3 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.2.4 |
| ibm | tivoli_storage_manager | 6.2.6 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 5.2.7 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
| ibm | tivoli_storage_manager | 6.2.7 |
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows local users to discover the backup/restore encryption-key password via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 5.5 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 6.4 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.2 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus_manufacturing_pack | 1.0.0.0 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq_explorer | 7.5.0.0 |
| ibm | websphere_mq_explorer | 7.5.0.4 |
| ibm | websphere_mq_explorer | 7.5.0.3 |
| ibm | websphere_mq_explorer | 8.0.0.1 |
| ibm | websphere_mq_explorer | 7.5.0.1 |
| ibm | websphere_mq_explorer | 7.5.0.2 |
| ibm | websphere_mq_explorer | 8.0.0.0 |
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile_appliance | 8.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not properly implement secure connections, which allows man-in-the-middle attackers to discover cleartext credentials via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 does not properly handle SSH connections, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to conduct clickjacking attacks via a crafted HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.0 |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_risk_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_risk_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_risk_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.4 |
| ibm | qradar_risk_manager | 7.2.0 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | qradar_risk_manager | 7.2.3 |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.1 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_risk_manager | 7.1.0 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.0 |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_risk_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_risk_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | serverguide | * |
| ibm | updatexpress_system_packs_installer | * |
| ibm | toolscenter_suite | * |
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attackers to execute arbitrary code via a crafted URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.2 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-358,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.2 |
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.0 |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.2 |
| ibm | qradar_risk_manager | 7.2.4 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_risk_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_risk_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_risk_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile_appliance | 8.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_appliance | 8.0 |
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (administration UI outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak SSL cipher.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure that HTTPS is used, which allows remote attackers to obtain sensitive information by sniffing the network during an HTTP session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak algorithm in an SSL cipher suite.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive information by sniffing the network during use of the null SSL cipher.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote authenticated users to cause a denial of service (disrupted system operations) by uploading a file to a protected area.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.3.0 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.0 |
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | * |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | * |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for remote attackers to obtain admin access via a brute-force approach.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.2.4 |
Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.2.0.8 |
| ibm | tivoli_directory_server | 6.3.0 |
| ibm | security_directory_server | 6.3.1.5 |
| ibm | tivoli_directory_server | 6.1.0.63 |
| ibm | tivoli_directory_server | 6.2.0.15 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.2.0.13 |
| ibm | tivoli_directory_server | 6.2.0.6 |
| ibm | tivoli_directory_server | 6.3.0.10 |
| ibm | tivoli_directory_server | 6.3.0.1 |
| ibm | tivoli_directory_server | 6.1.0.24 |
| ibm | tivoli_directory_server | 6.1.0.29 |
| ibm | tivoli_directory_server | 6.1.0.36 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | security_directory_server | 6.3.1 |
| ibm | tivoli_directory_server | 6.1.0.35 |
| ibm | tivoli_directory_server | 6.2.0.1 |
| ibm | tivoli_directory_server | 6.2.0.12 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.2.0.7 |
| ibm | tivoli_directory_server | 6.1.0.30 |
| ibm | security_directory_server | 6.3.1.1 |
| ibm | tivoli_directory_server | 6.2.0 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.2.0.10 |
| ibm | security_directory_server | 6.3.1.4 |
| ibm | tivoli_directory_server | 6.2.0.5 |
| ibm | tivoli_directory_server | 6.1.0.23 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.1.0.47 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.2.0.11 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.28 |
| ibm | tivoli_directory_server | 6.1.0.19 |
| ibm | tivoli_directory_server | 6.3.0.32 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | tivoli_directory_server | 6.1.0.34 |
| ibm | tivoli_directory_server | 6.2.0.22 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.1.0.20 |
| ibm | tivoli_directory_server | 6.2 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0.22 |
| ibm | tivoli_directory_server | 6.1.0.37 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.3.0.8 |
| ibm | tivoli_directory_server | 6.2.0.4 |
| ibm | tivoli_directory_server | 6.1.0.45 |
| ibm | tivoli_directory_server | 6.2.0.38 |
| ibm | tivoli_directory_server | 6.3.0.9 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.39 |
| ibm | tivoli_directory_server | 6.2.0.14 |
| ibm | tivoli_directory_server | 6.1.0.18 |
| ibm | tivoli_directory_server | 6.1.0.33 |
| ibm | security_directory_server | 6.3.1.3 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.3.0.2 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.27 |
| ibm | tivoli_directory_server | 6.1.0.48 |
| ibm | tivoli_directory_server | 6.1.0.25 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.21 |
| ibm | tivoli_directory_server | 6.1.0.31 |
| ibm | security_directory_server | 6.3.1.2 |
| ibm | tivoli_directory_server | 6.1.0.26 |
| ibm | tivoli_directory_server | 6.1.0.38 |
| ibm | tivoli_directory_server | 6.2.0.3 |
| ibm | tivoli_directory_server | 6.1.0.32 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 6.1.0.46 |
| ibm | tivoli_directory_server | 6.1.0.1 |
| ibm | security_directory_server | 6.3.1.6 |
| ibm | tivoli_directory_server | 6.1.0.17 |
Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 5.1.0.11 |
| ibm | security_identity_manager | 5.1.0 |
| ibm | security_identity_manager | 5.1.0.8 |
| ibm | security_identity_manager | 5.1.0.14 |
| ibm | security_identity_manager | 5.1.0.4 |
| ibm | security_identity_manager | 5.1.0.6 |
| ibm | security_identity_manager | 5.1.0.5 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 5.1.0.7 |
| ibm | security_identity_manager | 5.1.0.9 |
| ibm | security_identity_manager | 5.1.0.10 |
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 5.1.0.13 |
| ibm | security_identity_manager | 6.0.0.4 |
| ibm | security_identity_manager | 5.1.0.3 |
| ibm | security_identity_manager | 5.1.0.15 |
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_identity_manager | 5.1.0.12 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0 |
| ibm | tivoli_identity_manager | 5.1 |
| ibm | security_identity_manager | 7.0 |
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0 |
| ibm | tivoli_identity_manager | 5.1 |
| ibm | security_identity_manager | 7.0 |
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0 |
| ibm | tivoli_identity_manager | 5.1 |
| ibm | security_identity_manager | 7.0 |
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0 |
| ibm | tivoli_identity_manager | 5.1 |
| ibm | security_identity_manager | 7.0 |
Cross-site scripting (XSS) vulnerability in the Web Reports component in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | * |
The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Decision Management 7.5 before FP3 IF41; and Operational Decision Manager 8.0 before MP1 FP2 IF34, 8.5 before MP1 FP1 IF43, and 8.6 before IF8 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operational_decision_manager | 8.6 |
| ibm | operational_decision_manager | 8.0 |
| ibm | operational_decision_manager | 8.5 |
| ibm | websphere_ilog_jrules | 7.1 |
| ibm | websphere_operational_decision_management | 7.5 |
IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Reporting Service (JRS) report URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_insight | 1.1.1.5 |
The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.1 |
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to execute arbitrary code via a crafted executable file in an archive.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8 |
| ibm | security_appscan | 9.0 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan | 8.6 |
| ibm | security_appscan | 8.5 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.7 |
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan_source | 8.0.0.0 |
| ibm | security_appscan_source | 8.7 |
| ibm | rational_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 8.6.0.1 |
| ibm | security_appscan_source | 8.6.0.2 |
| ibm | security_appscan_source | 8.7.0.1 |
| ibm | rational_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 9.0.0.0 |
| ibm | rational_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | rational_appscan_source | 8.5.0.0 |
| ibm | security_appscan_source | 8.6.0.0 |
| ibm | security_appscan_source | 8.8 |
| ibm | security_appscan_source | 9.0.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8 |
| ibm | security_appscan | 9.0 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan | 8.6 |
| ibm | security_appscan | 8.5 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.7 |
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to write to arbitrary folders, and consequently execute arbitrary commands, via a modified argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8 |
| ibm | security_appscan | 9.0 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan | 8.6 |
| ibm | security_appscan | 8.5 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.7 |
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_appscan_source | 8.0.0.0 |
| ibm | rational_appscan_source | 8.0.0.1 |
| ibm | security_appscan_source | 8.6.0.1 |
| ibm | security_appscan_source | 8.6.0.2 |
| ibm | security_appscan_source | 8.7.0.1 |
| ibm | rational_appscan_source | 8.5.0.1 |
| ibm | security_appscan_source | 9.0.0.0 |
| ibm | rational_appscan_source | 8.0.0.2 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | rational_appscan_source | 8.5.0.0 |
| ibm | security_appscan_source | 8.6.0.0 |
| ibm | security_appscan_source | 9.0 |
| ibm | security_appscan_source | 8.7.0.0 |
| ibm | security_appscan_source | 8.8 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to delete the dashboards of arbitrary users via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 3.0.1.2 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.5 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | notes_traveler | * |
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to read the dashboards of arbitrary users via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 3.0.1.2 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.5 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 8.5 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
IBM API Management 3.x before 3.0.1.0 allows local users to obtain sensitive ciphertext information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 3.0.0.0 |
| ibm | api_management | 3.0.0.1 |
IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 8.0.1.5 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 8.0.0 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 8.0.1.6 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.0.13 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 8.0.0.12 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | installation_manager | * |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 8.0.1.4 |
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8 |
| ibm | security_appscan | 9.0 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan | 8.6 |
| ibm | security_appscan | 8.5 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.7 |
IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.1.1 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.0.0.3 |
| ibm | security_appscan | 8.8.0.0 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager | * |
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_endpoint_manager_mobile_device_management | * |
IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.1.4 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.1.0 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.5 |
| ibm | tivoli_monitoring | 6.2.3.3 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.2.1.3 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.0 |
| ibm | tivoli_monitoring | 6.3.0.4 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | tivoli_monitoring | 6.2.0.2 |
| ibm | tivoli_monitoring | 6.3.0.1 |
| ibm | tivoli_monitoring | 6.3.0.3 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.3.4 |
| ibm | tivoli_monitoring | 6.3.0.2 |
| ibm | tivoli_monitoring | 6.2.1.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.0.3 |
| ibm | tivoli_monitoring | 6.2.1 |
| ibm | tivoli_monitoring | 6.2.0.1 |
| ibm | tivoli_monitoring | 6.2.1.1 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 3.0.1.6 |
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2.1 |
| ibm | sterling_b2b_integrator | 5.2.4 |
| ibm | sterling_b2b_integrator | 5.2.2 |
IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flex_system_manager | 1.2.0 |
| ibm | flex_system_manager | 1.1.0 |
| ibm | flex_system_manager | 1.3.2.0 |
| ibm | flex_system_manager | 1.3.0 |
| ibm | flex_system_manager | 1.2.1 |
| ibm | flex_system_manager | 1.3.1 |
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.8 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.10 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.9 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.7 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.3 |
Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.8 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.10 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.9 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.7 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.0.3 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.6 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.5 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1 |
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_integrated_portal | 2.2 |
| ibm | tivoli_integrated_portal | 2.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_integrated_portal | 2.2 |
| ibm | tivoli_integrated_portal | 2.1 |
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 8.5 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | optim_performance_manager | 4.1.1.1 |
| ibm | optim_performance_manager | 5.1.0 |
| ibm | optim_performance_manager | 4.1.1 |
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 8.5 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3) Emergency Fixes component.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | pureapplication_system | 1.1.0.2 |
| ibm | pureapplication_system | 1.0.0.0 |
| ibm | pureapplication_system | 1.1.0.3 |
| ibm | pureapplication_system | 1.0.0.1 |
| ibm | pureapplication_system | 1.1.0.0 |
| ibm | pureapplication_system | 1.1.0.4 |
| ibm | pureapplication_system | 1.0.0.2 |
| ibm | pureapplication_system | 1.0.0.3 |
| ibm | pureapplication_system | 2.0.0.0 |
| ibm | pureapplication_system | 1.1.0.1 |
| ibm | workload_deployer | 3.1.0.7 |
IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 8.5 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact 6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netcool/impact | 6.1.1 |
Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 5.1.0.11 |
| ibm | security_identity_manager | 5.1.0 |
| ibm | security_identity_manager | 5.1.0.8 |
| ibm | security_identity_manager | 5.1.0.14 |
| ibm | security_identity_manager | 5.1.0.4 |
| ibm | security_identity_manager | 5.1.0.6 |
| ibm | security_identity_manager | 5.1.0.5 |
| ibm | security_identity_manager | 5.1.0.7 |
| ibm | security_identity_manager | 5.1.0.9 |
| ibm | security_identity_manager | 5.1.0.10 |
| ibm | security_identity_manager | 5.1.0.13 |
| ibm | security_identity_manager | 5.1.0.3 |
| ibm | security_identity_manager | 5.1.0.15 |
| ibm | security_identity_manager | 5.1.0.12 |
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_experience_builder | 8.5.1 |
| ibm | forms_experience_builder | 8.5 |
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 7.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | websphere_message_broker | 7.0. |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | websphere_message_broker | 7.0.0.7 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 3.0.2.0 |
| ibm | api_management | 3.0.0.0 |
| ibm | api_management | 3.0.4.0 |
| ibm | api_management | 3.0.3.0 |
| ibm | api_management | 3.0.0.1 |
| ibm | api_management | 3.0.2.1 |
Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_operations | 7.4.2.7 |
| ibm | marketing_operations | 7.3.2.0 |
| ibm | marketing_operations | 8.1.0.7 |
| ibm | marketing_operations | 8.1.1.0 |
| ibm | marketing_operations | 7.5.3.7 |
| ibm | marketing_operations | 8.2.0.5 |
| ibm | marketing_operations | 7.2.0.4 |
| ibm | marketing_operations | 7.4.0.0 |
| ibm | marketing_operations | 8.2.0.8 |
| ibm | marketing_operations | 8.2.0.10 |
| ibm | marketing_operations | 9.0.0.2 |
| ibm | marketing_operations | 7.4.2.0 |
| ibm | marketing_operations | 8.0.0.0 |
| ibm | marketing_operations | 8.6.0.6 |
| ibm | marketing_operations | 8.6.0.5 |
| ibm | marketing_operations | 8.2.0.9 |
| ibm | marketing_operations | 9.0.0.3 |
| ibm | marketing_operations | 9.1.0.4 |
| ibm | marketing_operations | 8.0.0.2 |
| ibm | marketing_operations | 9.0.0.1 |
| ibm | marketing_operations | 8.2.0.6 |
| ibm | marketing_operations | 8.5.0.7 |
| ibm | marketing_operations | 8.2.0.12 |
| ibm | marketing_operations | 7.3.2.8 |
| ibm | marketing_operations | 9.1.1.0 |
| ibm | marketing_operations | 8.1.0.0 |
| ibm | marketing_operations | 8.1.0.6 |
| ibm | marketing_operations | 8.6.0.0 |
| ibm | marketing_operations | 7.5.3.9 |
| ibm | marketing_operations | 8.2.0.7 |
| ibm | marketing_operations | 8.2.0.11 |
| ibm | marketing_operations | 8.5.0.2 |
| ibm | marketing_operations | 8.5.0.6 |
| ibm | marketing_operations | 8.5.0.3 |
| ibm | marketing_operations | 9.1.1.1 |
| ibm | marketing_operations | 8.6.0.4 |
| ibm | marketing_operations | 8.6.0.7 |
| ibm | marketing_operations | 7.4.1.6 |
| ibm | marketing_operations | 8.1.1.4 |
| ibm | marketing_operations | 8.5.0.4 |
| ibm | marketing_operations | 9.0.0.4 |
| ibm | marketing_operations | 7.4.1.0 |
| ibm | marketing_operations | 7.5.0.0 |
| ibm | marketing_operations | 7.2.1.0 |
| ibm | marketing_operations | 7.5.0.1 |
| ibm | marketing_operations | 8.5.0.5 |
| ibm | marketing_operations | 7.5.3.0 |
| ibm | marketing_operations | 7.5.2.0 |
| ibm | marketing_operations | 9.0.0.0 |
| ibm | marketing_operations | 9.1.0.3 |
| ibm | marketing_operations | 8.2.0.13 |
| ibm | marketing_operations | 8.6.0.3 |
| ibm | marketing_operations | 8.5.0.1 |
| ibm | marketing_operations | 7.2.1.12 |
| ibm | marketing_operations | 8.6.0.2 |
| ibm | marketing_operations | 8.5.0.0 |
| ibm | marketing_operations | 8.2.0.0 |
| ibm | marketing_operations | 7.2.0.0 |
| ibm | marketing_operations | 7.5.2.3 |
| ibm | marketing_operations | 9.1.0.2 |
| ibm | marketing_operations | 9.1.0.0 |
| ibm | marketing_operations | 7.5.3.8 |
| ibm | marketing_operations | 7.4.0.2 |
| ibm | marketing_operations | 7.3.2.1 |
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere_enterprise_service_bus | 7.0 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | websphere_process_server | 7.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.3 does not perform access-control checks for depth-0 retrieve operations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.5.0.3 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent header.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 does not perform access-control checks for contained objects, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_firmware | 5.1 |
| ibm | security_network_protection_firmware | 5.1.1 |
| ibm | security_network_protection_firmware | 5.2.0.0 |
| ibm | security_network_protection_firmware | 5.3 |
| ibm | security_network_protection_xgs_5000 | * |
| ibm | security_network_protection_firmware | 5.1.0.0 |
| ibm | security_network_protection_xgs_5100 | - |
| ibm | security_network_protection_firmware | 5.1.1.0 |
| ibm | security_network_protection_firmware | 5.1.2.1 |
| ibm | security_network_protection_firmware | 5.1.2.0 |
Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through 5.5.4.3, 6.1 through 6.1.5.6, 6.2 before 6.2.5.4, and 6.3 before 6.3.2.3 on UNIX, Linux, and OS X allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.4.0.7 |
| ibm | tivoli_storage_manager | 6.4.1.7 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.1.3 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.0.4 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.0 |
| ibm | tivoli_storage_manager | 6.4.0.5 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.4.0.1 |
| ibm | tivoli_storage_manager | 6.4.0 |
| ibm | tivoli_storage_manager | 6.3.2.1 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 6.3.0 |
IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.1 allows remote authenticated users to bypass intended object-access restrictions via the datagraph.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 |
| ibm | websphere_service_registry_and_repository | 8.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 |
| ibm | websphere_service_registry_and_repository | 7.0.0 |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_3100_firmware | 5.3 |
| ibm | security_network_protection_4100_firmware | 5.2 |
| ibm | security_network_protection_5100_firmware | 5.2 |
| ibm | security_network_protection_7100_firmware | 5.2 |
| ibm | security_network_protection_7100_firmware | 5.3 |
| ibm | security_network_protection_5100_firmware | 5.3 |
| ibm | security_network_protection_4100_firmware | 5.3 |
| ibm | security_network_protection_3100_firmware | 5.2 |
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | workload_deployer | 3.1.0.6 |
| ibm | workload_deployer | 3.1.0.2 |
| ibm | workload_deployer | 3.1.0 |
| ibm | workload_deployer | 3.1.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.5.5a |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Windows, before 6.2.5.3 on AIX and Linux x86, and before 6.2.5.4 on Linux Z and Solaris; 6.3 before 6.3.2.1 on AIX, before 6.3.2.2 on Windows, and before 6.3.2.3 on Linux; 6.4 before 6.4.2.1; and 7.1 before 7.1.1 in IBM TSM for Mail, when the Data Protection for Lotus Domino component is used, allow local users to bypass authentication and restore a Domino database or transaction-log backup via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 5.4 |
| ibm | tivoli_storage_manager | 6.2 |
| ibm | tivoli_storage_manager | 5.5 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.4 |
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_experience_factory | 7.0.1.1 |
| ibm | web_experience_factory | 6.1.5 |
| ibm | web_experience_factory | 8.0.0 |
| ibm | web_experience_factory | 8.0.0.2 |
| ibm | web_experience_factory | 7.0.1.2 |
| ibm | web_experience_factory | 7.0.1.3 |
| ibm | web_experience_factory | 8.0.0.1 |
| ibm | web_experience_factory | 8.5.0.1 |
| ibm | web_experience_factory | 7.0.1.4 |
| ibm | web_experience_factory | 8.0 |
| ibm | web_experience_factory | 7.0.1 |
| ibm | web_experience_factory | 8.0.0.3 |
| ibm | web_experience_factory | 8.5 |
IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_xgs_firmware | 5.1 |
| ibm | security_network_protection_xgs_firmware | 5.3 |
| ibm | security_network_protection_xgs_firmware | 5.1.2.1 |
| ibm | security_network_protection_xgs_firmware | 5.1.2 |
| ibm | security_network_protection_xgs_firmware | 5.2 |
| ibm | security_network_protection_xgs_firmware | 5.1.1 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_firmware | 5.3 |
The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial of service (connection-slot exhaustion) via a crafted HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_b2b_integrator | 5.2.1 |
| ibm | sterling_b2b_integrator | 5.2.5.0 |
| ibm | sterling_b2b_integrator | 5.2.4.2 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_b2b_integrator | 5.2.4 |
| ibm | sterling_file_gateway | 2.1 |
| ibm | sterling_b2b_integrator | 5.2.2 |
| ibm | sterling_b2b_integrator | 5.2.4.1 |
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying the same column within multiple ALTER TABLE statements.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 through 8, when debugging is configured, do not properly restrict the logging of personal data, which allows local users to obtain sensitive information by reading a log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing_portfolio | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_program_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.0.1 |
| ibm | emptoris_program_management | 10.0.1.1 |
| ibm | emptoris_program_management | 10.0.2.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.0 |
| ibm | emptoris_program_management | 10.0.0.2 |
| ibm | emptoris_program_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.0 |
| ibm | emptoris_program_management | 10.0.1.0 |
| ibm | emptoris_program_management | 10.0.1.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.3 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.3 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.0 |
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.2 |
| ibm | emptoris_program_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_sourcing_portfolio | 10.0.1.1 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris | strategic_supply_management |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_program_management | 10.0.2.4 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.2 |
| ibm | emptoris_program_management | 10.0.0.3 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.2 |
| ibm | emptoris_sourcing_portfolio | 10.0.0.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.0.1 |
| ibm | emptoris_program_management | 10.0.2.0 |
| ibm | emptoris_sourcing_portfolio | 9.5.1.1 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_sourcing_portfolio | 10.0.2.4 |
| ibm | emptoris_program_management | 10.0.0.0 |
| ibm | emptoris_program_management | 10.0.1.2 |
| ibm | emptoris_program_management | 10.0.2.3 |
| ibm | emptoris_contract_management | 9.5.0.6 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.1.0 |
| ibm | websphere_portal | 8.5.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 8.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.0.5 |
The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate random numbers, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | 8.0.0.10 |
| ibm | rational_clearcase | 7.1.2.3 |
| ibm | rational_clearcase | 8.0.0.1 |
| ibm | rational_clearcase | 8.0.1.6 |
| ibm | rational_clearcase | 7.1.2.13 |
| ibm | rational_clearcase | 8.0.1 |
| ibm | rational_clearcase | 8.0.0.13 |
| ibm | rational_clearcase | 8.0.0.12 |
| ibm | rational_clearcase | 7.1.2.16 |
| ibm | rational_clearcase | 7.1.2.4 |
| ibm | rational_clearcase | 8.0.0.7 |
| ibm | rational_clearcase | 7.1.2.11 |
| ibm | rational_clearcase | 8.0.0.3 |
| ibm | rational_clearcase | 8.0.0.6 |
| ibm | rational_clearcase | 7.1.2.1 |
| ibm | rational_clearcase | 8.0.0.8 |
| ibm | rational_clearcase | 7.1.2.15 |
| ibm | rational_clearcase | 7.1.2.14 |
| ibm | rational_clearcase | 7.1.2.2 |
| ibm | rational_clearcase | 8.0.1.5 |
| ibm | rational_clearcase | 8.0.0.9 |
| ibm | rational_clearcase | 8.0.0 |
| ibm | rational_clearcase | 8.0.1.3 |
| ibm | rational_clearcase | 8.0.0.2 |
| ibm | rational_clearcase | 8.0.0.11 |
| ibm | rational_clearcase | 8.0.1.1 |
| ibm | rational_clearcase | 8.0.1.2 |
| ibm | rational_clearcase | 7.1.2.5 |
| ibm | rational_clearcase | 7.1.2.12 |
| ibm | rational_clearcase | 7.1.2 |
| ibm | rational_clearcase | 8.0.0.4 |
| ibm | rational_clearcase | 7.1.2.9 |
| ibm | rational_clearcase | 8.0.0.5 |
| ibm | rational_clearcase | 7.1.2.7 |
| ibm | rational_clearcase | 7.1.2.6 |
| ibm | rational_clearcase | 8.0.1.4 |
| ibm | rational_clearcase | 7.1.2.10 |
Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_operations | 7.4.2.7 |
| ibm | marketing_operations | 7.3.2.0 |
| ibm | marketing_operations | 8.1.0.7 |
| ibm | marketing_operations | 8.1.1.0 |
| ibm | marketing_operations | 7.5.3.7 |
| ibm | marketing_operations | 8.2.0.5 |
| ibm | marketing_operations | 7.2.0.4 |
| ibm | marketing_operations | 7.4.0.0 |
| ibm | marketing_operations | 8.2.0.8 |
| ibm | marketing_operations | 8.2.0.10 |
| ibm | marketing_operations | 9.0.0.2 |
| ibm | marketing_operations | 7.4.2.0 |
| ibm | marketing_operations | 8.0.0.0 |
| ibm | marketing_operations | 8.6.0.6 |
| ibm | marketing_operations | 8.6.0.5 |
| ibm | marketing_operations | 8.2.0.9 |
| ibm | marketing_operations | 9.0.0.3 |
| ibm | marketing_operations | 9.1.0.4 |
| ibm | marketing_operations | 8.0.0.2 |
| ibm | marketing_operations | 9.0.0.1 |
| ibm | marketing_operations | 8.2.0.6 |
| ibm | marketing_operations | 8.5.0.7 |
| ibm | marketing_operations | 8.2.0.12 |
| ibm | marketing_operations | 7.3.2.8 |
| ibm | marketing_operations | 9.1.1.0 |
| ibm | marketing_operations | 8.1.0.0 |
| ibm | marketing_operations | 8.1.0.6 |
| ibm | marketing_operations | 8.6.0.0 |
| ibm | marketing_operations | 7.5.3.9 |
| ibm | marketing_operations | 8.2.0.7 |
| ibm | marketing_operations | 8.2.0.11 |
| ibm | marketing_operations | 8.5.0.2 |
| ibm | marketing_operations | 8.5.0.6 |
| ibm | marketing_operations | 8.5.0.3 |
| ibm | marketing_operations | 9.1.1.1 |
| ibm | marketing_operations | 8.6.0.4 |
| ibm | marketing_operations | 8.6.0.7 |
| ibm | marketing_operations | 7.4.1.6 |
| ibm | marketing_operations | 8.1.1.4 |
| ibm | marketing_operations | 8.5.0.4 |
| ibm | marketing_operations | 9.0.0.4 |
| ibm | marketing_operations | 7.4.1.0 |
| ibm | marketing_operations | 7.5.0.0 |
| ibm | marketing_operations | 7.2.1.0 |
| ibm | marketing_operations | 7.5.0.1 |
| ibm | marketing_operations | 8.5.0.5 |
| ibm | marketing_operations | 7.5.3.0 |
| ibm | marketing_operations | 7.5.2.0 |
| ibm | marketing_operations | 9.0.0.0 |
| ibm | marketing_operations | 9.1.0.3 |
| ibm | marketing_operations | 8.2.0.13 |
| ibm | marketing_operations | 8.6.0.3 |
| ibm | marketing_operations | 8.5.0.1 |
| ibm | marketing_operations | 7.2.1.12 |
| ibm | marketing_operations | 8.6.0.2 |
| ibm | marketing_operations | 8.5.0.0 |
| ibm | marketing_operations | 8.2.0.0 |
| ibm | marketing_operations | 7.2.0.0 |
| ibm | marketing_operations | 7.5.2.3 |
| ibm | marketing_operations | 9.1.0.2 |
| ibm | marketing_operations | 9.1.0.0 |
| ibm | marketing_operations | 7.5.3.8 |
| ibm | marketing_operations | 7.4.0.2 |
| ibm | marketing_operations | 7.3.2.1 |
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | pureapplication_system | * |
| redhat | enterprise_linux_server_aus | 5.9 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.5_ppc64 |
| redhat | enterprise_linux_server_aus | 6.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux | 5.0 |
| suse | linux_enterprise_software_development_kit | 12 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_for_power_big_endian | 7.0_ppc64 |
| vmware | esx | 4.1 |
| ibm | smartcloud_provisioning | 2.1.0 |
| suse | linux_enterprise_desktop | 12 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.6_ppc64 |
| redhat | enterprise_linux | 4.0 |
| debian | debian_linux | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| f5 | big-ip_global_traffic_manager | * |
| ibm | smartcloud_entry_appliance | 3.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| gnu | bash | * |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| f5 | big-ip_edge_gateway | * |
| oracle | linux | 5 |
| redhat | enterprise_linux_server_from_rhui | 7.0 |
| redhat | enterprise_linux_eus | 7.3 |
| novell | open_enterprise_server | 2.0 |
| suse | linux_enterprise_server | 10 |
| redhat | enterprise_linux_for_power_big_endian | 5.9_ppc |
| redhat | enterprise_linux_for_power_big_endian | 6.4_ppc64 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.9_s390x |
| redhat | enterprise_linux_server_aus | 7.3 |
| canonical | ubuntu_linux | 12.04 |
| ibm | smartcloud_entry_appliance | 2.3.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| f5 | big-ip_local_traffic_manager | 11.6.0 |
| f5 | traffix_signaling_delivery_controller | 3.5.1 |
| vmware | esx | 4.0 |
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_server_tus | 7.7 |
| f5 | big-ip_access_policy_manager | * |
| mageia | mageia | 3.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| redhat | virtualization | 3.4 |
| ibm | starter_kit_for_cloud | 2.2.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| oracle | linux | 4 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | flex_system_v7000_firmware | * |
| redhat | enterprise_linux_for_ibm_z_systems | 7.3_s390x |
| redhat | enterprise_linux_for_ibm_z_systems | 7.6_s390x |
| checkpoint | security_gateway | * |
| f5 | traffix_signaling_delivery_controller | 3.3.2 |
| ibm | pureapplication_system | 2.0.0.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.4_s390x |
| redhat | enterprise_linux_server_aus | 6.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| f5 | big-ip_local_traffic_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| f5 | big-ip_wan_optimization_manager | * |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| vmware | vcenter_server_appliance | 5.0 |
| f5 | big-ip_application_acceleration_manager | * |
| ibm | workload_deployer | * |
| ibm | stn6800_firmware | * |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.3_ppc64 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | smartcloud_entry_appliance | 2.4.0 |
| ibm | infosphere_guardium_database_activity_monitoring | 9.1 |
| novell | zenworks_configuration_management | 10.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.8.15 |
| suse | studio_onsite | 1.3 |
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| ibm | storwize_v5000_firmware | * |
| f5 | big-iq_cloud | * |
| vmware | vcenter_server_appliance | 5.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.9 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| opensuse | opensuse | 12.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | stn6500_firmware | * |
| redhat | enterprise_linux_for_ibm_z_systems | 7.5_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc |
| ibm | infosphere_guardium_database_activity_monitoring | 8.2 |
| redhat | enterprise_linux_server_from_rhui | 6.0 |
| f5 | traffix_signaling_delivery_controller | 4.1.0 |
| redhat | enterprise_linux_eus | 7.5 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| ibm | qradar_vulnerability_manager | 7.2.6 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | gluster_storage_server_for_on-premise | 2.1 |
| ibm | infosphere_guardium_database_activity_monitoring | 9.0 |
| f5 | big-ip_advanced_firewall_manager | 11.6.0 |
| redhat | enterprise_linux_server_tus | 7.6 |
| ibm | software_defined_network_for_virtual_environments | * |
| oracle | linux | 6 |
| ibm | qradar_security_information_and_event_manager | 7.1.1 |
| suse | linux_enterprise_desktop | 11 |
| vmware | vcenter_server_appliance | 5.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux_server_tus | 7.3 |
| ibm | storwize_v3700_firmware | * |
| f5 | big-ip_application_security_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| f5 | big-iq_device | * |
| qnap | qts | 4.1.1 |
| ibm | qradar_security_information_and_event_manager | 7.1.2 |
| f5 | big-ip_protocol_security_module | * |
| opensuse | opensuse | 13.2 |
| redhat | enterprise_linux_eus | 5.9 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_server | 7.0 |
| ibm | storwize_v3500_firmware | * |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.4_ppc64 |
| ibm | qradar_security_information_and_event_manager | 7.2 |
| f5 | big-ip_analytics | 11.6.0 |
| f5 | big-ip_application_security_manager | 11.6.0 |
| novell | open_enterprise_server | 11.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| suse | linux_enterprise_server | 12 |
| citrix | netscaler_sdx_firmware | * |
| f5 | big-ip_policy_enforcement_manager | * |
| canonical | ubuntu_linux | 10.04 |
| novell | zenworks_configuration_management | 11.3.0 |
| f5 | big-ip_link_controller | 11.6.0 |
| f5 | big-ip_policy_enforcement_manager | 11.6.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| f5 | enterprise_manager | * |
| f5 | traffix_signaling_delivery_controller | * |
| redhat | enterprise_linux_eus | 7.6 |
| f5 | big-ip_advanced_firewall_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| novell | zenworks_configuration_management | 11.2 |
| opensuse | opensuse | 13.1 |
| redhat | enterprise_linux_eus | 7.4 |
| suse | linux_enterprise_software_development_kit | 11 |
| arista | eos | * |
| ibm | smartcloud_entry_appliance | 3.1.0 |
| f5 | arx_firmware | * |
| redhat | enterprise_linux_eus | 6.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 6.4_s390x |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.5_ppc64 |
| f5 | big-ip_access_policy_manager | 11.6.0 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 |
| ibm | storwize_v7000_firmware | * |
| f5 | traffix_signaling_delivery_controller | 3.4.1 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_tus | 6.5 |
| f5 | big-ip_application_acceleration_manager | 11.6.0 |
| f5 | big-ip_analytics | * |
| apple | mac_os_x | * |
| redhat | enterprise_linux_server_aus | 5.6 |
| redhat | enterprise_linux_eus | 6.5 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
| ibm | san_volume_controller_firmware | * |
| mageia | mageia | 4.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.7_s390x |
| novell | zenworks_configuration_management | 11 |
| f5 | big-iq_security | * |
| f5 | big-ip_global_traffic_manager | 11.6.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| novell | zenworks_configuration_management | 11.1 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
| redhat | enterprise_linux_server_from_rhui | 5.0 |
| ibm | stn7800_firmware | * |
| ibm | qradar_vulnerability_manager | 7.2.8 |
| f5 | big-ip_webaccelerator | * |
| redhat | enterprise_linux_for_ibm_z_systems | 6.5_s390x |
| ibm | qradar_risk_manager | 7.1.0 |
| qnap | qts | * |
| redhat | enterprise_linux_server | 5.0 |
| f5 | big-ip_link_controller | * |
| redhat | enterprise_linux_server_aus | 7.6 |
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | pureapplication_system | * |
| redhat | enterprise_linux_server_aus | 5.9 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.5_ppc64 |
| redhat | enterprise_linux_server_aus | 6.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux | 5.0 |
| suse | linux_enterprise_software_development_kit | 12 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_for_power_big_endian | 7.0_ppc64 |
| vmware | esx | 4.1 |
| ibm | smartcloud_provisioning | 2.1.0 |
| suse | linux_enterprise_desktop | 12 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.6_ppc64 |
| redhat | enterprise_linux | 4.0 |
| debian | debian_linux | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| f5 | big-ip_global_traffic_manager | * |
| ibm | smartcloud_entry_appliance | 3.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| gnu | bash | * |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| f5 | big-ip_edge_gateway | * |
| oracle | linux | 5 |
| redhat | enterprise_linux_server_from_rhui | 7.0 |
| redhat | enterprise_linux_eus | 7.3 |
| novell | open_enterprise_server | 2.0 |
| suse | linux_enterprise_server | 10 |
| redhat | enterprise_linux_for_power_big_endian | 5.9_ppc |
| redhat | enterprise_linux_for_power_big_endian | 6.4_ppc64 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.9_s390x |
| redhat | enterprise_linux_server_aus | 7.3 |
| canonical | ubuntu_linux | 12.04 |
| ibm | smartcloud_entry_appliance | 2.3.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| f5 | big-ip_local_traffic_manager | 11.6.0 |
| f5 | traffix_signaling_delivery_controller | 3.5.1 |
| vmware | esx | 4.0 |
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_server_tus | 7.7 |
| f5 | big-ip_access_policy_manager | * |
| mageia | mageia | 3.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| redhat | virtualization | 3.4 |
| ibm | starter_kit_for_cloud | 2.2.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| oracle | linux | 4 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | flex_system_v7000_firmware | * |
| redhat | enterprise_linux_for_ibm_z_systems | 7.3_s390x |
| redhat | enterprise_linux_for_ibm_z_systems | 7.6_s390x |
| checkpoint | security_gateway | * |
| f5 | traffix_signaling_delivery_controller | 3.3.2 |
| ibm | pureapplication_system | 2.0.0.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.4_s390x |
| redhat | enterprise_linux_server_aus | 6.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| f5 | big-ip_local_traffic_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| f5 | big-ip_wan_optimization_manager | * |
| ibm | qradar_vulnerability_manager | 7.2.2 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| vmware | vcenter_server_appliance | 5.0 |
| f5 | big-ip_application_acceleration_manager | * |
| ibm | workload_deployer | * |
| ibm | stn6800_firmware | * |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.3_ppc64 |
| ibm | qradar_vulnerability_manager | 7.2.3 |
| ibm | smartcloud_entry_appliance | 2.4.0 |
| ibm | infosphere_guardium_database_activity_monitoring | 9.1 |
| novell | zenworks_configuration_management | 10.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.8.15 |
| suse | studio_onsite | 1.3 |
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| ibm | storwize_v5000_firmware | * |
| f5 | big-iq_cloud | * |
| vmware | vcenter_server_appliance | 5.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.9 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| opensuse | opensuse | 12.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | stn6500_firmware | * |
| redhat | enterprise_linux_for_ibm_z_systems | 7.5_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc |
| ibm | infosphere_guardium_database_activity_monitoring | 8.2 |
| redhat | enterprise_linux_server_from_rhui | 6.0 |
| f5 | traffix_signaling_delivery_controller | 4.1.0 |
| redhat | enterprise_linux_eus | 7.5 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| ibm | qradar_vulnerability_manager | 7.2.6 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | gluster_storage_server_for_on-premise | 2.1 |
| ibm | infosphere_guardium_database_activity_monitoring | 9.0 |
| f5 | big-ip_advanced_firewall_manager | 11.6.0 |
| redhat | enterprise_linux_server_tus | 7.6 |
| ibm | software_defined_network_for_virtual_environments | * |
| oracle | linux | 6 |
| ibm | qradar_security_information_and_event_manager | 7.1.1 |
| suse | linux_enterprise_desktop | 11 |
| vmware | vcenter_server_appliance | 5.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux_server_tus | 7.3 |
| ibm | storwize_v3700_firmware | * |
| f5 | big-ip_application_security_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| f5 | big-iq_device | * |
| qnap | qts | 4.1.1 |
| ibm | qradar_security_information_and_event_manager | 7.1.2 |
| f5 | big-ip_protocol_security_module | * |
| opensuse | opensuse | 13.2 |
| redhat | enterprise_linux_eus | 5.9 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_server | 7.0 |
| ibm | storwize_v3500_firmware | * |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.4_ppc64 |
| ibm | qradar_security_information_and_event_manager | 7.2 |
| f5 | big-ip_analytics | 11.6.0 |
| f5 | big-ip_application_security_manager | 11.6.0 |
| novell | open_enterprise_server | 11.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| suse | linux_enterprise_server | 12 |
| citrix | netscaler_sdx_firmware | * |
| f5 | big-ip_policy_enforcement_manager | * |
| canonical | ubuntu_linux | 10.04 |
| novell | zenworks_configuration_management | 11.3.0 |
| f5 | big-ip_link_controller | 11.6.0 |
| f5 | big-ip_policy_enforcement_manager | 11.6.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| f5 | enterprise_manager | * |
| f5 | traffix_signaling_delivery_controller | * |
| redhat | enterprise_linux_eus | 7.6 |
| f5 | big-ip_advanced_firewall_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| novell | zenworks_configuration_management | 11.2 |
| opensuse | opensuse | 13.1 |
| redhat | enterprise_linux_eus | 7.4 |
| suse | linux_enterprise_software_development_kit | 11 |
| arista | eos | * |
| ibm | smartcloud_entry_appliance | 3.1.0 |
| f5 | arx_firmware | * |
| redhat | enterprise_linux_eus | 6.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 6.4_s390x |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.5_ppc64 |
| f5 | big-ip_access_policy_manager | 11.6.0 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 |
| ibm | storwize_v7000_firmware | * |
| f5 | traffix_signaling_delivery_controller | 3.4.1 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_tus | 6.5 |
| f5 | big-ip_application_acceleration_manager | 11.6.0 |
| f5 | big-ip_analytics | * |
| apple | mac_os_x | * |
| redhat | enterprise_linux_server_aus | 5.6 |
| redhat | enterprise_linux_eus | 6.5 |
| ibm | qradar_vulnerability_manager | 7.2.1 |
| ibm | san_volume_controller_firmware | * |
| mageia | mageia | 4.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.7_s390x |
| novell | zenworks_configuration_management | 11 |
| f5 | big-iq_security | * |
| f5 | big-ip_global_traffic_manager | 11.6.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| novell | zenworks_configuration_management | 11.1 |
| ibm | qradar_vulnerability_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_vulnerability_manager | 7.2.0 |
| redhat | enterprise_linux_server_from_rhui | 5.0 |
| ibm | stn7800_firmware | * |
| ibm | qradar_vulnerability_manager | 7.2.8 |
| f5 | big-ip_webaccelerator | * |
| redhat | enterprise_linux_for_ibm_z_systems | 6.5_s390x |
| ibm | qradar_risk_manager | 7.1.0 |
| qnap | qts | * |
| redhat | enterprise_linux_server | 5.0 |
| f5 | big-ip_link_controller | * |
| redhat | enterprise_linux_server_aus | 7.6 |
IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_operations | 7.4.2.7 |
| ibm | marketing_operations | 7.3.2.0 |
| ibm | marketing_operations | 8.1.0.7 |
| ibm | marketing_operations | 8.1.1.0 |
| ibm | marketing_operations | 7.5.3.7 |
| ibm | marketing_operations | 8.2.0.5 |
| ibm | marketing_operations | 7.2.0.4 |
| ibm | marketing_operations | 7.4.0.0 |
| ibm | marketing_operations | 8.2.0.8 |
| ibm | marketing_operations | 8.2.0.10 |
| ibm | marketing_operations | 9.0.0.2 |
| ibm | marketing_operations | 7.4.2.0 |
| ibm | marketing_operations | 8.0.0.0 |
| ibm | marketing_operations | 8.6.0.6 |
| ibm | marketing_operations | 8.6.0.5 |
| ibm | marketing_operations | 8.2.0.9 |
| ibm | marketing_operations | 9.0.0.3 |
| ibm | marketing_operations | 9.1.0.4 |
| ibm | marketing_operations | 8.0.0.2 |
| ibm | marketing_operations | 9.0.0.1 |
| ibm | marketing_operations | 8.2.0.6 |
| ibm | marketing_operations | 8.5.0.7 |
| ibm | marketing_operations | 8.2.0.12 |
| ibm | marketing_operations | 7.3.2.8 |
| ibm | marketing_operations | 9.1.1.0 |
| ibm | marketing_operations | 8.1.0.0 |
| ibm | marketing_operations | 8.1.0.6 |
| ibm | marketing_operations | 8.6.0.0 |
| ibm | marketing_operations | 7.5.3.9 |
| ibm | marketing_operations | 8.2.0.7 |
| ibm | marketing_operations | 8.2.0.11 |
| ibm | marketing_operations | 8.5.0.2 |
| ibm | marketing_operations | 8.5.0.6 |
| ibm | marketing_operations | 8.5.0.3 |
| ibm | marketing_operations | 9.1.1.1 |
| ibm | marketing_operations | 8.6.0.4 |
| ibm | marketing_operations | 8.6.0.7 |
| ibm | marketing_operations | 7.4.1.6 |
| ibm | marketing_operations | 8.1.1.4 |
| ibm | marketing_operations | 8.5.0.4 |
| ibm | marketing_operations | 9.0.0.4 |
| ibm | marketing_operations | 7.4.1.0 |
| ibm | marketing_operations | 7.5.0.0 |
| ibm | marketing_operations | 7.2.1.0 |
| ibm | marketing_operations | 7.5.0.1 |
| ibm | marketing_operations | 8.5.0.5 |
| ibm | marketing_operations | 7.5.3.0 |
| ibm | marketing_operations | 7.5.2.0 |
| ibm | marketing_operations | 9.0.0.0 |
| ibm | marketing_operations | 9.1.0.3 |
| ibm | marketing_operations | 8.2.0.13 |
| ibm | marketing_operations | 8.6.0.3 |
| ibm | marketing_operations | 8.5.0.1 |
| ibm | marketing_operations | 7.2.1.12 |
| ibm | marketing_operations | 8.6.0.2 |
| ibm | marketing_operations | 8.5.0.0 |
| ibm | marketing_operations | 8.2.0.0 |
| ibm | marketing_operations | 7.2.0.0 |
| ibm | marketing_operations | 7.5.2.3 |
| ibm | marketing_operations | 9.1.0.2 |
| ibm | marketing_operations | 9.1.0.0 |
| ibm | marketing_operations | 7.5.3.8 |
| ibm | marketing_operations | 7.4.0.2 |
| ibm | marketing_operations | 7.3.2.1 |
IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java_sdk | * |
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to bypass intended access permissions and obtain sensitive information via unspecified vectors related to the security manager.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java_sdk | * |
Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.2.2 |
Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.2.2 |
IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.2.1 |
| ibm | tririga_application_platform | 3.3.2.2 |
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.3 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.8 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.7 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 11.4 |
| ibm | infosphere_master_data_management_collaborative_server | 10.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.6 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.3 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_collaborative_server | 11.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 11.3 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8898 and CVE-2014-8899.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.3 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.8 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.7 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 11.4 |
| ibm | infosphere_master_data_management_collaborative_server | 10.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.6 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.3 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_collaborative_server | 11.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 11.3 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8899.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.3 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.8 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.7 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 11.4 |
| ibm | infosphere_master_data_management_collaborative_server | 10.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.6 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.3 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_collaborative_server | 11.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 11.3 |
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8898.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.3 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.8 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.5 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.7 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.2 |
| ibm | infosphere_master_data_management_collaborative_server | 11.4 |
| ibm | infosphere_master_data_management_collaborative_server | 10.1.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.6 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0.0.3 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.4 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1.0 |
| ibm | infosphere_master_data_management_collaborative_server | 11.0 |
| ibm | infosphere_master_data_management_collaborative_server | 10.0.0.1 |
| ibm | infosphere_master_data_management_collaborative_server | 11.3 |
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | * |
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 9.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.0.4.9 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.6 |
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.2.2.2 |
| ibm | vios | 2.2.2.5 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote attackers to inject arbitrary web script or HTML via the Accept-Language HTTP header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.1 |
| ibm | content_navigator | 2.0.0 |
| ibm | content_navigator | 2.0.3 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 6.0.0.2 |
| ibm | websphere_portal | 6.1.0 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 6.0.1.0 |
| ibm | websphere_portal | 6.0.1.1 |
| ibm | websphere_portal | 6.0.0.4 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 6.0.1.3 |
| ibm | websphere_portal | 6.0.0.1 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.0 |
| ibm | websphere_portal | 6.0.1.4 |
| ibm | websphere_portal | 6.1 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.0.1.6 |
| ibm | websphere_portal | 6.0.1.2 |
| ibm | websphere_portal | 6.0 |
| ibm | websphere_portal | 6.0.1.5 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.0.0.3 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.0.1.7 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.5 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8914.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.0.0.0 |
| ibm | financial_transaction_manager_for_corporate_payment_services | 2.1.1.0 |
| ibm | financial_transaction_manager | 2.0.0.3 |
| ibm | financial_transaction_manager | 2.1.0.2 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 2.1.0.0 |
| ibm | social_media_analytics | * |
| ibm | financial_transaction_manager | 2.1.1.0 |
| ibm | financial_transaction_manager_for_check_services | 2.1.1.8 |
| ibm | financial_transaction_manager | 2.0.0.2 |
| ibm | financial_transaction_manager | 2.1.1.1 |
| ibm | financial_transaction_manager | 2.0.0.1 |
| ibm | financial_transaction_manager | 2.1.0.1 |
IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.0.0.1 |
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.1.1 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 8.6.0.1 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 8.0.0.3 |
| ibm | security_appscan | 8.8.0.0 |
| ibm | security_appscan | 8.5.0.1 |
| ibm | security_appscan | 8.0.0.2 |
| ibm | security_appscan | 8.0.0.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 8.5.0.0 |
Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | 5r4 |
| ibm | i_access | 6.1 |
| ibm | i_access | 7.1 |
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | notes_traveler_companion | 1.1 |
| ibm | notes_traveler_companion | 1.0 |
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_active_directory_adapter | * |
| ibm | tivoli_identity_manager_active_directory_adapter | * |
The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 7.5 |
| ibm | license_metric_tool | 7.2.2 |
| ibm | tivoli_asset_discovery_for_distributed | 7.5 |
| ibm | tivoli_asset_discovery_for_distributed | 7.2.2 |
Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 8.0.0.12 |
| ibm | rational_clearquest | 8.0.0.5 |
| ibm | rational_clearquest | 8.0.1.2 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 8.0.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1 |
| ibm | rational_clearquest | 7.1.2.15 |
| ibm | rational_clearquest | 8.0.0.9 |
| ibm | rational_clearquest | 8.0.0.11 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 8.0.0 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.11 |
| ibm | rational_clearquest | 7.1.2.12 |
| ibm | rational_clearquest | 7.1.0.1 |
| ibm | rational_clearquest | 7.1.2.13 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.0.2 |
| ibm | rational_clearquest | 8.0.0.7 |
| ibm | rational_clearquest | 8.0.0.10 |
| ibm | rational_clearquest | 8.0.1.3 |
| ibm | rational_clearquest | 8.0.1.5 |
| ibm | rational_clearquest | 8.0.1 |
| ibm | rational_clearquest | 8.0.1.4 |
| ibm | rational_clearquest | 7.1.2.7 |
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.1.9 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.8 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.2.14 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.2.9 |
| ibm | rational_clearquest | 7.1.2.10 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0.6 |
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_family | 9.0 |
| ibm | license_metric_tool | 7.5 |
| ibm | license_metric_tool | 7.2.2 |
| ibm | tivoli_asset_discovery_for_distributed | 7.5 |
| ibm | tivoli_asset_discovery_for_distributed | 7.2.2.0 |
| ibm | license_metric_tool | 9.0.1 |
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_family | 9.0 |
| ibm | license_metric_tool | 7.5 |
| ibm | license_metric_tool | 9.0 |
| ibm | license_metric_tool | 7.2.2 |
| ibm | tivoli_asset_discovery_for_distributed | 7.5 |
| ibm | tivoli_asset_discovery_for_distributed | 7.2.2.0 |
CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and resulting web cache poisoning or cross-site scripting (XSS) attacks, or obtain sensitive information via multiple unspecified parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-93,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | en6131_firmware | - |
| ibm | ib6131_firmware | - |
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ib6131_firmware | * |
| ibm | en6131_firmware | * |
IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_netview_access_services | - |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5 |
| ibm | business_process_manager | 8.0 |
| ibm | business_process_manager | 8.0.1 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 7.5 |
| ibm | business_process_manager | 7.5.1 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
Multiple cross-site scripting (XSS) vulnerabilities in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified data fields.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2 |
| ibm | websphere_application_server | 7.2.0.3 |
| ibm | websphere_application_server | 7.2.0.2 |
| ibm | websphere_application_server | 7.2.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_application_server | 7.2.0.1 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere_application_server | 7.2.0.5 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | websphere_application_server | 7.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_application_server | 7.2.0.3 |
| ibm | websphere_application_server | 7.2.0.2 |
| ibm | websphere_application_server | 7.2.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_application_server | 7.2.0.1 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere_application_server | 7.2.0.0 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere_application_server | 7.2.0.5 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Requirements Composer (RRC) 2.0 through 2.0.0.4, 3.x before 3.0.1.6 IF6, and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF5 and 5.x before 5.0.2 IF4; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2; and Rational Software Architect Design Manager (RSA DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 3.0.1.2 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rhapsody_design_manager | 4.0.0 |
| ibm | rhapsody_design_manager | 4.0.5 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_requirements_composer | 3.5 |
| ibm | rhapsody_design_manager | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rhapsody_design_manager | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rhapsody_design_manager | 4.0.7 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rhapsody_design_manager | 4.0.2 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rhapsody_design_manager | 3.0.0 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rhapsody_design_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rhapsody_design_manager | 3.0.1 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rhapsody_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.1 |
| ibm | rational_software_architect_design_manager | 3.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rhapsody_design_manager | 5.0 |
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Engineering Lifecycle Manager 4.0.3 through 4.0.7 and 5.0 through 5.0.2, Rational Rhapsody Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, and Rational Software Architect Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2 allows remote attackers to read JSP source code via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access_for_windows | 7.1 |
| ibm | i_access_for_windows | 6.1 |
| ibm | i_access_for_windows | 5.4 |
Cross-site request forgery (CSRF) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to hijack the authentication of customer accounts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | leads | 9.1.1 |
| ibm | leads | 9.0.0 |
| ibm | leads | 7.1.1 |
| ibm | leads | 8.2.0 |
| ibm | leads | 9.1.0 |
| ibm | leads | 7.1.0 |
| ibm | leads | 8.5.0 |
| ibm | leads | 8.1.0 |
| ibm | leads | 7.5.0 |
| ibm | leads | 8.6.0 |
IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict the addition of links, which makes it easier for remote authenticated users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | leads | 9.1.1 |
| ibm | leads | 9.0.0 |
| ibm | leads | 7.1.1 |
| ibm | leads | 8.2.0 |
| ibm | leads | 9.1.0 |
| ibm | leads | 7.1.0 |
| ibm | leads | 8.5.0 |
| ibm | leads | 8.1.0 |
| ibm | leads | 7.5.0 |
| ibm | leads | 8.6.0 |
The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, aka SPR KLYH9SLRGM.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection to an Integration Bus node.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | websphere_message_broker | 7.0. |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | * |
Buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 has unspecified impact and remote attack vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_requirements_composer | 4.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0123.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_team_concert | 5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0122.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_team_concert | 5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0128.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 3.0.1.6 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | leads | 9.1.1 |
| ibm | leads | 9.0.0 |
| ibm | leads | 7.1.1 |
| ibm | leads | 8.2.0 |
| ibm | leads | 9.1.0 |
| ibm | leads | 7.1.0 |
| ibm | leads | 8.5.0 |
| ibm | leads | 8.1.0 |
| ibm | leads | 7.5.0 |
| ibm | leads | 8.6.0 |
IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | leads | 9.1.1 |
| ibm | leads | 9.0.0 |
| ibm | leads | 7.1.1 |
| ibm | leads | 8.2.0 |
| ibm | leads | 9.1.0 |
| ibm | leads | 7.1.0 |
| ibm | leads | 8.5.0 |
| ibm | leads | 8.1.0 |
| ibm | leads | 7.5.0 |
| ibm | leads | 8.6.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0124.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 2.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 2.0.1.1 |
| ibm | rational_quality_manager | 2.0.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 3.0.1.6 |
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.1 |
Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirements Composer (RRC) 4.x through 4.0.7; and Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | leads | 9.1.1 |
| ibm | leads | 9.0.0 |
| ibm | leads | 7.1.1 |
| ibm | leads | 8.2.0 |
| ibm | leads | 9.1.0 |
| ibm | leads | 7.1.0 |
| ibm | leads | 8.5.0 |
| ibm | leads | 8.1.0 |
| ibm | leads | 7.5.0 |
| ibm | leads | 8.6.0 |
The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_requirements_composer | 4.0 |
IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and 9.0.1 before FP2 IF3 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.0.3 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.0.0 |
| ibm | powervc | 1.2.1.1 |
| ibm | powervc | 1.2.1.0 |
IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.0.3 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.0.0 |
| ibm | powervc | 1.2.1.1 |
| ibm | powervc | 1.2.1.0 |
GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.1.5 |
| ibm | tivoli_directory_server | * |
| ibm | tivoli_directory_server | 6.2.0.29 |
| ibm | tivoli_directory_server | 6.2.0.6 |
| ibm | tivoli_directory_server | 6.3.0.10 |
| ibm | tivoli_directory_server | 6.3.0.1 |
| ibm | tivoli_directory_server | 6.1.0.24 |
| ibm | tivoli_directory_server | 6.1.0.36 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | tivoli_directory_server | 6.2.0.12 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.1.0.40 |
| ibm | tivoli_directory_server | 6.3.1.8 |
| ibm | tivoli_directory_server | 6.3.0.31 |
| ibm | tivoli_directory_server | 6.2.0.26 |
| ibm | tivoli_directory_server | 6.2.0.10 |
| ibm | tivoli_directory_server | 6.2.0.32 |
| ibm | tivoli_directory_server | 6.2.0.30 |
| ibm | tivoli_directory_server | 6.2.0.35 |
| ibm | tivoli_directory_server | 6.3.0.24 |
| ibm | tivoli_directory_server | 6.3.0.25 |
| ibm | tivoli_directory_server | 6.1.0.23 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.1.0.47 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.52 |
| ibm | tivoli_directory_server | 6.1.0.28 |
| ibm | tivoli_directory_server | 6.1.0.54 |
| ibm | tivoli_directory_server | 6.2.0.33 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | tivoli_directory_server | 6.2.0.23 |
| ibm | tivoli_directory_server | 6.1.0.34 |
| ibm | tivoli_directory_server | 6.1.0.53 |
| ibm | tivoli_directory_server | 6.3.0.11 |
| ibm | tivoli_directory_server | 6.3.0.15 |
| ibm | tivoli_directory_server | 6.1.0.51 |
| ibm | tivoli_directory_server | 6.1.0.57 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0.22 |
| ibm | tivoli_directory_server | 6.1.0.61 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.2.0.36 |
| ibm | tivoli_directory_server | 6.3.0.8 |
| ibm | tivoli_directory_server | 6.3.0.34 |
| ibm | tivoli_directory_server | 6.1.0.45 |
| ibm | tivoli_directory_server | 6.2.0.38 |
| ibm | tivoli_directory_server | 6.3.0.17 |
| ibm | tivoli_directory_server | 6.3.0.9 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.18 |
| ibm | tivoli_directory_server | 6.1.0.33 |
| ibm | tivoli_directory_server | 6.3.0.2 |
| ibm | tivoli_directory_server | 6.1.0.27 |
| ibm | tivoli_directory_server | 6.1.0.58 |
| ibm | tivoli_directory_server | 6.3.1.7 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.31 |
| ibm | tivoli_directory_server | 6.1.0.38 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 6.1.0.50 |
| ibm | tivoli_directory_server | 6.3.0.22 |
| ibm | tivoli_directory_server | 6.1.0.42 |
| ibm | tivoli_directory_server | 6.2.0.42 |
| ibm | tivoli_directory_server | 6.3.0.19 |
| ibm | tivoli_directory_server | 6.2.0.8 |
| ibm | tivoli_directory_server | 6.1.0.44 |
| ibm | tivoli_directory_server | 6.1.0.63 |
| ibm | tivoli_directory_server | 6.2.0.15 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.3.0.27 |
| ibm | tivoli_directory_server | 6.2.0.27 |
| ibm | tivoli_directory_server | 6.1.0.41 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.2.0.13 |
| ibm | tivoli_directory_server | 6.1.0.59 |
| ibm | tivoli_directory_server | 6.1.0.29 |
| ibm | tivoli_directory_server | 6.1.0.35 |
| ibm | tivoli_directory_server | 6.2.0.1 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.3.0.26 |
| ibm | tivoli_directory_server | 6.1.0.66 |
| ibm | tivoli_directory_server | 6.2.0.7 |
| ibm | tivoli_directory_server | 6.3.0.12 |
| ibm | tivoli_directory_server | 6.3.0.30 |
| ibm | tivoli_directory_server | 6.1.0.30 |
| ibm | tivoli_directory_server | 6.3.1.9 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.2.0.31 |
| ibm | tivoli_directory_server | 6.1.0.49 |
| ibm | tivoli_directory_server | 6.3.0.33 |
| ibm | tivoli_directory_server | 6.2.0.5 |
| ibm | tivoli_directory_server | 6.2.0.24 |
| ibm | tivoli_directory_server | 6.1.0.55 |
| ibm | tivoli_directory_server | 6.2.0.25 |
| ibm | tivoli_directory_server | 6.3.0.21 |
| ibm | tivoli_directory_server | 6.2.0.11 |
| ibm | tivoli_directory_server | 6.2.0.34 |
| ibm | tivoli_directory_server | 6.3.1.6 |
| ibm | tivoli_directory_server | 6.1.0.19 |
| ibm | tivoli_directory_server | 6.3.0.32 |
| ibm | tivoli_directory_server | 6.3.0.35 |
| ibm | tivoli_directory_server | 6.3.0.18 |
| ibm | tivoli_directory_server | 6.2.0.22 |
| ibm | tivoli_directory_server | 6.1.0.62 |
| ibm | tivoli_directory_server | 6.2.0.41 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.1.0.20 |
| ibm | tivoli_directory_server | 6.3.0.23 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.2.0.40 |
| ibm | tivoli_directory_server | 6.1.0.37 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.2.0.4 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.3.0.14 |
| ibm | tivoli_directory_server | 6.2.0.37 |
| ibm | tivoli_directory_server | 6.1.0.39 |
| ibm | tivoli_directory_server | 6.2.0.14 |
| ibm | tivoli_directory_server | 6.1.0.60 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.1.0.64 |
| ibm | tivoli_directory_server | 6.1.0.43 |
| ibm | tivoli_directory_server | 6.1.0.65 |
| ibm | tivoli_directory_server | 6.3.0.28 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.48 |
| ibm | tivoli_directory_server | 6.3.0.29 |
| ibm | tivoli_directory_server | 6.1.0.25 |
| ibm | tivoli_directory_server | 6.1.0.56 |
| ibm | tivoli_directory_server | 6.2.0.39 |
| ibm | tivoli_directory_server | 6.1.0.21 |
| ibm | tivoli_directory_server | 6.1.0.26 |
| ibm | tivoli_directory_server | 6.2.0.3 |
| ibm | tivoli_directory_server | 6.1.0.32 |
| ibm | tivoli_directory_server | 6.1.0.46 |
| ibm | tivoli_directory_server | 6.1.0.1 |
| ibm | tivoli_directory_server | 6.1.0.17 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_statistics | 22.0 |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and data-storage outage) by calling the System Administration Mode function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 6.2.0.0 |
| ibm | openpages_grc_platform | 6.2.1.1 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 6.2.1.0 |
IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_collector | 3.0.0.1 |
| ibm | content_collector | 3.0.0.2 |
| ibm | content_collector | 4.0.0.1 |
| ibm | content_collector | 4.0.0.0 |
| ibm | content_collector | 3.0.0.0 |
| ibm | content_collector | 3.0.0.3 |
| ibm | content_collector | 3.0.0.4 |
| ibm | content_collector | 4.0.0.2 |
| ibm | content_collector | 3.0.0.5 |
The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 3.0.2.0 |
| ibm | api_management | 3.0.0.0 |
| ibm | api_management | 3.0.4.0 |
| ibm | api_management | 3.0.3.0 |
| ibm | api_management | 3.0.2.1 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | websphere | 7.2.0.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere | 7.2.0.4 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere | 7.2.0.1 |
| ibm | websphere | 7.2.0.3 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | websphere | 7.2.0.5 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere | 7.2 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary commands with SYSTEM privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
SQL injection vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.1.0 |
Cross-site scripting (XSS) vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arguments via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
Directory traversal vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to write to arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.1.0.2 |
| ibm | security_siteprotector_system | 3.0.0.1 |
| ibm | security_siteprotector_system | 3.0.0.3 |
| ibm | security_siteprotector_system | 3.0.0.4 |
| ibm | security_siteprotector_system | 3.0.0.2 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.0.1 |
| ibm | security_siteprotector_system | 3.0.0.5 |
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.0.0.6 |
| ibm | security_siteprotector_system | 3.1.0.3 |
| ibm | security_siteprotector_system | 3.1.1.0 |
| ibm | security_siteprotector_system | 3.1.1.1 |
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors. IBM X-Force ID: 100927.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_siteprotector_system | 3.0 |
| ibm | security_siteprotector_system | 3.1.0.0 |
| ibm | security_siteprotector_system | 3.1.1.0 |
The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier for remote attackers to bypass intended restrictions on MQ message data by predicting an ID value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_internet_pass_thru | * |
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URI that is included in an error response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | liberty | * |
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.1 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
The cluster repository manager in IBM WebSphere MQ 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allows remote authenticated administrators to cause a denial of service (memory overwrite and daemon outage) by triggering multiple transmit-queue records.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 8.0 |
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| suse | linux_enterprise_server | 10 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_server_aus | 6.6 |
| suse | linux_enterprise_software_development_kit | 12 |
| redhat | enterprise_linux_desktop | 5.0 |
| ibm | java | * |
| redhat | enterprise_linux_server_eus | 7.4 |
| suse | linux_enterprise_server | 12 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_server_eus | 6.6 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.1 |
| redhat | enterprise_linux_server | 5.0 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL that triggers an error condition.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | websphere | 7.2.0.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere | 7.2.0.4 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere | 7.2.0.1 |
| ibm | websphere | 7.2.0.3 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | websphere | 7.2.0.5 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere | 7.2 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
| ibm | sterling_file_gateway | 2.2 |
| ibm | sterling_file_gateway | 2.1 |
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_template_catalog | * |
CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 4.1 |
| ibm | general_parallel_file_system | 3.4 |
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 4.1 |
| ibm | general_parallel_file_system | 3.4 |
The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 4.1 |
| ibm | general_parallel_file_system | 3.4 |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | communications_policy_management | 9.7.3 |
| php | php | * |
| debian | debian_linux | 8.0 |
| oracle | communications_policy_management | 12.1.1 |
| oracle | communications_webrtc_session_controller | 7.2 |
| ibm | pureapplication_system | 1.1.0.0 |
| oracle | communications_policy_management | 10.4.1 |
| oracle | communications_eagle_lnp_application_processor | 10.0 |
| oracle | linux | 7 |
| redhat | virtualization | 6.0 |
| debian | debian_linux | 7.0 |
| oracle | exalogic_infrastructure | 1.0 |
| oracle | exalogic_infrastructure | 2.0 |
| ibm | security_access_manager_for_enterprise_single_sign-on | 8.2 |
| oracle | vm_virtualbox | * |
| oracle | communications_policy_management | 9.9.1 |
| oracle | communications_application_session_controller | * |
| apple | mac_os_x | * |
| oracle | linux | 5 |
| oracle | communications_session_border_controller | 7.2.0 |
| oracle | communications_webrtc_session_controller | 7.1 |
| oracle | communications_session_border_controller | * |
| oracle | communications_user_data_repository | * |
| oracle | communications_lsms | 13.1 |
| gnu | glibc | * |
| oracle | communications_webrtc_session_controller | 7.0 |
| ibm | pureapplication_system | 1.0.0.0 |
| oracle | communications_policy_management | 11.5 |
| oracle | communications_eagle_application_processor | 16.0 |
| ibm | pureapplication_system | 2.0.0.0 |
| oracle | communications_session_border_controller | 8.0.0 |
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | hive | 1.0.0 |
| ibm | infosphere_biginsights | 3.0.0.1 |
| apache | hive | 1.1.0 |
| ibm | infosphere_biginsights | 3.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.2 |
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| apache | hbase | 0.98.9 |
| apache | hbase | 0.98.10 |
| apache | hbase | 0.98.8 |
| apache | hbase | 0.98.3 |
| ibm | infosphere_biginsights | 3.0.0.1 |
| apache | hbase | 0.98.11 |
| apache | hbase | 0.98.0 |
| ibm | infosphere_biginsights | 3.0.0.0 |
| apache | hbase | 0.98.6.1 |
| apache | hbase | 0.98.6 |
| apache | hbase | 0.98.4 |
| apache | hbase | 0.98.12 |
| apache | hbase | 0.98.2 |
| apache | hbase | 0.98.7 |
| apache | hbase | 0.98.1 |
| apache | hbase | 0.98.10.1 |
| ibm | infosphere_biginsights | 3.0.0.2 |
| apache | hbase | 0.98.5 |
Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | websphere | 7.2.0.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere | 7.2.0.4 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere | 7.2.0.1 |
| ibm | websphere | 7.2.0.3 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | websphere | 7.2.0.5 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere | 7.2 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundation, Content Manager OnDemand, and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.2 |
| ibm | content_navigator | 2.0.3 |
The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 3.0.0.1 |
| ibm | infosphere_biginsights | 3.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.2 |
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 4.1 |
The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | * |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | optim_workload_replay | 2.1 |
| ibm | optim_workload_replay | 2.1.0.1 |
| ibm | optim_workload_replay | 2.1.0.2 |
IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass intended access restrictions by modifying the client behavior.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | optim_workload_replay | 2.1 |
| ibm | optim_workload_replay | 2.1.0.1 |
| ibm | optim_workload_replay | 2.1.0.2 |
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1898.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1897.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_datastage | 11.3 |
| ibm | infosphere_datastage | 11.3.1 |
| ibm | infosphere_datastage | 8.5 |
| ibm | infosphere_datastage | 9.1 |
| ibm | infosphere_datastage | 8.7 |
| ibm | infosphere_datastage | 11.3.1.2 |
| ibm | infosphere_datastage | 8.1 |
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 11.3.1 |
| ibm | infosphere_information_server | 8.7.0.2 |
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 8.7 |
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSMLA.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSN3Y.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authenticated users to read cookies via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.1.4.5 |
| ibm | rational_license_key_server | 8.1.4 |
| ibm | rational_license_key_server | 8.1.4.4 |
| ibm | rational_license_key_server | 8.1.4.3 |
| ibm | rational_license_key_server | 8.1.4.6 |
| ibm | rational_license_key_server | 8.1.4.2 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.4 |
Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_field_sales | 9.0 |
| ibm | sterling_order_management | 8.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.0 |
Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.5.0.x before 8.5.0.4, 8.5.1.x before 8.5.1.5, 8.6.0.x before 8.6.0.4, and 8.7.0.x before 8.7.0.2 uses the MD5 algorithm for password hashing, which makes it easier for remote attackers to bypass authentication via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_test_workbench | 8.5.1.1 |
| ibm | rational_test_virtualization_server | 8.0.0.1 |
| ibm | rational_test_virtualization_server | 8.5.0 |
| ibm | rational_test_virtualization_server | 8.6.0.1 |
| ibm | rational_test_workbench | 8.0.1 |
| ibm | rational_test_workbench | 8.5.1.3 |
| ibm | rational_test_virtualization_server | 8.5.1.2 |
| ibm | rational_test_virtualization_server | 8.5.1 |
| ibm | rational_test_workbench | 8.5.0.1 |
| ibm | rational_test_workbench | 8.0.0.4 |
| ibm | rational_test_virtualization_server | 8.5.1.4 |
| ibm | rational_test_workbench | 8.5.1 |
| ibm | rational_test_workbench | 8.0.1.2 |
| ibm | rational_test_workbench | 8.0.1.3 |
| ibm | rational_test_virtualization_server | 8.7.0.1 |
| ibm | rational_test_workbench | 8.6.0.1 |
| ibm | rational_test_virtualization_server | 8.6.0 |
| ibm | rational_test_workbench | 8.7.0.1 |
| ibm | rational_test_virtualization_server | 8.5.0.3 |
| ibm | rational_test_virtualization_server | 8.0.1.4 |
| ibm | rational_test_workbench | 8.0.0 |
| ibm | rational_test_workbench | 8.7.0 |
| ibm | rational_test_virtualization_server | 8.0.0.2 |
| ibm | rational_test_workbench | 8.5.1.4 |
| ibm | rational_test_virtualization_server | 8.5.0.1 |
| ibm | rational_test_workbench | 8.6.0.3 |
| ibm | rational_test_workbench | 8.5.0 |
| ibm | rational_test_workbench | 8.5.0.3 |
| ibm | rational_test_workbench | 8.0.0.1 |
| ibm | rational_test_workbench | 8.6.0.2 |
| ibm | rational_test_virtualization_server | 8.0.1.5 |
| ibm | rational_test_virtualization_server | 8.7.0 |
| ibm | rational_test_workbench | 8.0.0.2 |
| ibm | rational_test_virtualization_server | 8.5.1.3 |
| ibm | rational_test_virtualization_server | 8.5.0.2 |
| ibm | rational_test_virtualization_server | 8.6.0.2 |
| ibm | rational_test_virtualization_server | 8.0.1.2 |
| ibm | rational_test_workbench | 8.0.1.4 |
| ibm | rational_test_workbench | 8.6.0 |
| ibm | rational_test_workbench | 8.0.1.1 |
| ibm | rational_test_virtualization_server | 8.0.0.3 |
| ibm | rational_test_workbench | 8.5.0.2 |
| ibm | rational_test_workbench | 8.0.1.5 |
| ibm | rational_test_virtualization_server | 8.0.1 |
| ibm | rational_test_virtualization_server | 8.0.1.3 |
| ibm | rational_test_virtualization_server | 8.5.1.1 |
| ibm | rational_test_virtualization_server | 8.6.0.3 |
| ibm | rational_test_virtualization_server | 8.0.0 |
| ibm | rational_test_virtualization_server | 8.0.0.4 |
| ibm | rational_test_workbench | 8.0.0.3 |
| ibm | rational_test_workbench | 8.5.1.2 |
| ibm | rational_test_virtualization_server | 8.0.1.1 |
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | * |
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_family | 9.1.0 |
| ibm | endpoint_manager_family | 9.0.1 |
Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 8.0 |
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar Incident Forensics before 7.2.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | * |
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.0.47 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Engineering Lifecycle Manager (RELM) 4.0.3 through 4.0.7, 5.0 through 5.0.2, and 6.0.0; Rational Rhapsody Design Manager (DM) 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0.0; and Rational Software Architect Design Manager (DM) 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0.0 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_virtual_enterprise | * |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not have an off autocomplete attribute for the password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.0.2 |
| ibm | powervc | 1.2.1.2 |
| ibm | powervc | 1.2.2.0 |
| ibm | powervc | 1.2.0.3 |
| ibm | powervc | 1.2.2.1 |
| ibm | powervc | 1.2.0.1 |
| ibm | powervc | 1.2.2.2 |
| ibm | powervc | 1.2.0.0 |
| ibm | powervc | 1.2.1.1 |
| ibm | powervc | 1.2.0.4 |
| ibm | powervc | 1.2.1.0 |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1986.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute these files, via a crafted TCP packet to an unspecified port.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_virtual_enterprise | 7.0.0.2 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_virtual_enterprise | 7.0.0.1 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_virtual_enterprise | 7.0.0.4 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_virtual_enterprise | 7.0 |
| ibm | websphere_virtual_enterprise | 7.0.0.5 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_virtual_enterprise | 7.0.0.3 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
Untrusted search path vulnerability in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0, when a DB2 database is used, allows local users to gain privileges via a Trojan horse library that is loaded by a setuid or setgid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 3.0.0.1 |
| ibm | infosphere_biginsights | 4.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.2 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powervc | 1.2.2.1 |
| ibm | powervc | 1.2.2.2 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8.0.0 |
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 9.0.2.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.6.0.0 |
| ibm | security_appscan | 8.5.0.0 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1964, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1965.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1964.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_common_reporting | 3.1.0.0 |
| ibm | tivoli_common_reporting | 3.1.0.1 |
| ibm | tivoli_common_reporting | 2.1.0.0 |
| ibm | tivoli_common_reporting | 3.1.2 |
| ibm | tivoli_common_reporting | 2.1.1.0 |
| ibm | tivoli_common_reporting | 3.1.0.2 |
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.3 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.2 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.0 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.3 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5.0.4 |
Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Requirements Composer (RRC) 2.x and 3.x before 3.0.1.6 IF7 and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0; and Rational Software Architect Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote attackers to cause a denial of service via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | * |
| ibm | security_directory_server | * |
Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.40 |
| ibm | tivoli_directory_server | 6.3.1.5 |
| ibm | security_directory_server | 6.3.1.10 |
| ibm | security_directory_server | 6.3.1.17 |
| ibm | tivoli_directory_server | 6.1.0.69 |
| ibm | tivoli_directory_server | 6.2.0.29 |
| ibm | tivoli_directory_server | 6.2.0.6 |
| ibm | tivoli_directory_server | 6.3.0.10 |
| ibm | tivoli_directory_server | 6.3.0.1 |
| ibm | tivoli_directory_server | 6.1.0.24 |
| ibm | tivoli_directory_server | 6.2.0.47 |
| ibm | security_directory_server | 6.4.0.1 |
| ibm | tivoli_directory_server | 6.1.0.36 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.1.0.14 |
| ibm | security_directory_server | 6.3.1 |
| ibm | tivoli_directory_server | 6.2.0.12 |
| ibm | tivoli_directory_server | 6.1.0.2 |
| ibm | tivoli_directory_server | 6.1.0.40 |
| ibm | tivoli_directory_server | 6.3.1.8 |
| ibm | tivoli_directory_server | 6.3.0.31 |
| ibm | tivoli_directory_server | 6.1.0.70 |
| ibm | tivoli_directory_server | 6.2.0 |
| ibm | tivoli_directory_server | 6.2.0.26 |
| ibm | security_directory_server | 6.3.1.13 |
| ibm | tivoli_directory_server | 6.2.0.10 |
| ibm | tivoli_directory_server | 6.2.0.32 |
| ibm | tivoli_directory_server | 6.2.0.30 |
| ibm | tivoli_directory_server | 6.2.0.35 |
| ibm | tivoli_directory_server | 6.2.0.44 |
| ibm | security_directory_server | 6.3.1.0 |
| ibm | security_directory_server | 6.3.1.11 |
| ibm | tivoli_directory_server | 6.3.0.24 |
| ibm | tivoli_directory_server | 6.3.0.25 |
| ibm | tivoli_directory_server | 6.1.0.23 |
| ibm | security_directory_server | 6.4.0.6 |
| ibm | tivoli_directory_server | 6.1.0.3 |
| ibm | tivoli_directory_server | 6.1.0.47 |
| ibm | tivoli_directory_server | 6.2.0.0 |
| ibm | tivoli_directory_server | 6.1.0.8 |
| ibm | tivoli_directory_server | 6.1.0.52 |
| ibm | tivoli_directory_server | 6.1.0.28 |
| ibm | tivoli_directory_server | 6.1.0.54 |
| ibm | tivoli_directory_server | 6.2.0.33 |
| ibm | tivoli_directory_server | 6.1.0.72 |
| ibm | tivoli_directory_server | 6.2.0.20 |
| ibm | security_directory_server | 6.3.1.15 |
| ibm | tivoli_directory_server | 6.2.0.23 |
| ibm | tivoli_directory_server | 6.1.0.34 |
| ibm | tivoli_directory_server | 6.3.0.37 |
| ibm | tivoli_directory_server | 6.1.0.53 |
| ibm | tivoli_directory_server | 6.3.0.11 |
| ibm | tivoli_directory_server | 6.3.0.15 |
| ibm | tivoli_directory_server | 6.2.0.48 |
| ibm | tivoli_directory_server | 6.1.0.51 |
| ibm | tivoli_directory_server | 6.1.0.57 |
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0.22 |
| ibm | security_directory_server | 6.4.0.0 |
| ibm | tivoli_directory_server | 6.1.0.61 |
| ibm | security_directory_server | 6.3.1.8 |
| ibm | tivoli_directory_server | 6.1.0.7 |
| ibm | tivoli_directory_server | 6.2.0.36 |
| ibm | tivoli_directory_server | 6.3.0.8 |
| ibm | tivoli_directory_server | 6.3.0.34 |
| ibm | tivoli_directory_server | 6.1.0.45 |
| ibm | tivoli_directory_server | 6.2.0.38 |
| ibm | tivoli_directory_server | 6.3.0.17 |
| ibm | tivoli_directory_server | 6.3.0.9 |
| ibm | security_directory_server | 6.4.0.8 |
| ibm | tivoli_directory_server | 6.1.0.12 |
| ibm | tivoli_directory_server | 6.1.0.18 |
| ibm | tivoli_directory_server | 6.1.0.33 |
| ibm | tivoli_directory_server | 6.3.0.2 |
| ibm | tivoli_directory_server | 6.1.0.27 |
| ibm | tivoli_directory_server | 6.1.0.58 |
| ibm | security_directory_server | 6.3.1.14 |
| ibm | tivoli_directory_server | 6.3.1.7 |
| ibm | tivoli_directory_server | 6.3.0.36 |
| ibm | security_directory_server | 6.4.0.5 |
| ibm | tivoli_directory_server | 6.1.0.10 |
| ibm | tivoli_directory_server | 6.1.0.31 |
| ibm | tivoli_directory_server | 6.1.0.38 |
| ibm | security_directory_server | 6.4.0.7 |
| ibm | tivoli_directory_server | 6.2.0.21 |
| ibm | tivoli_directory_server | 6.1.0.50 |
| ibm | tivoli_directory_server | 6.3.0.22 |
| ibm | security_directory_server | 6.3.1.9 |
| ibm | tivoli_directory_server | 6.1.0.42 |
| ibm | tivoli_directory_server | 6.2.0.42 |
| ibm | tivoli_directory_server | 6.3.0.19 |
| ibm | tivoli_directory_server | 6.2.0.8 |
| ibm | tivoli_directory_server | 6.1.0.44 |
| ibm | tivoli_directory_server | 6.3.0.38 |
| ibm | tivoli_directory_server | 6.3.0 |
| ibm | security_directory_server | 6.3.1.5 |
| ibm | tivoli_directory_server | 6.1.0.63 |
| ibm | tivoli_directory_server | 6.2.0.15 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.3.0.27 |
| ibm | tivoli_directory_server | 6.2.0.27 |
| ibm | tivoli_directory_server | 6.1.0.41 |
| ibm | tivoli_directory_server | 6.1.0.9 |
| ibm | tivoli_directory_server | 6.2.0.13 |
| ibm | tivoli_directory_server | 6.1.0.59 |
| ibm | tivoli_directory_server | 6.2.0.45 |
| ibm | tivoli_directory_server | 6.1.0.29 |
| ibm | security_directory_server | 6.4.0.4 |
| ibm | tivoli_directory_server | 6.1.0.35 |
| ibm | tivoli_directory_server | 6.2.0.1 |
| ibm | tivoli_directory_server | 6.2.0.19 |
| ibm | tivoli_directory_server | 6.2.0.43 |
| ibm | security_directory_server | 6.3.1.7 |
| ibm | tivoli_directory_server | 6.3.0.26 |
| ibm | tivoli_directory_server | 6.1.0.66 |
| ibm | tivoli_directory_server | 6.2.0.7 |
| ibm | tivoli_directory_server | 6.3.0.12 |
| ibm | tivoli_directory_server | 6.3.0.30 |
| ibm | tivoli_directory_server | 6.1.0.30 |
| ibm | tivoli_directory_server | 6.3.1.9 |
| ibm | security_directory_server | 6.3.1.1 |
| ibm | security_directory_server | 6.3.1.16 |
| ibm | tivoli_directory_server | 6.2.0.2 |
| ibm | tivoli_directory_server | 6.2.0.31 |
| ibm | tivoli_directory_server | 6.1.0.49 |
| ibm | security_directory_server | 6.3.1.4 |
| ibm | tivoli_directory_server | 6.2.0.46 |
| ibm | security_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.3.0.33 |
| ibm | tivoli_directory_server | 6.2.0.5 |
| ibm | tivoli_directory_server | 6.2.0.24 |
| ibm | tivoli_directory_server | 6.1.0.71 |
| ibm | tivoli_directory_server | 6.1.0.55 |
| ibm | tivoli_directory_server | 6.1.0.73 |
| ibm | tivoli_directory_server | 6.2.0.25 |
| ibm | tivoli_directory_server | 6.3.0.21 |
| ibm | tivoli_directory_server | 6.2.0.11 |
| ibm | tivoli_directory_server | 6.1.0.68 |
| ibm | tivoli_directory_server | 6.2.0.34 |
| ibm | tivoli_directory_server | 6.3.1.6 |
| ibm | tivoli_directory_server | 6.2.0.49 |
| ibm | tivoli_directory_server | 6.1.0.19 |
| ibm | tivoli_directory_server | 6.3.0.32 |
| ibm | tivoli_directory_server | 6.3.0.35 |
| ibm | tivoli_directory_server | 6.3.0.18 |
| ibm | tivoli_directory_server | 6.2.0.22 |
| ibm | tivoli_directory_server | 6.1.0.62 |
| ibm | tivoli_directory_server | 6.2.0.41 |
| ibm | tivoli_directory_server | 6.1.0.6 |
| ibm | tivoli_directory_server | 6.1.0.4 |
| ibm | tivoli_directory_server | 6.1.0.20 |
| ibm | security_directory_server | 6.4.0.2 |
| ibm | tivoli_directory_server | 6.3.0.23 |
| ibm | tivoli_directory_server | 6.1.0.67 |
| ibm | tivoli_directory_server | 6.1.0.13 |
| ibm | tivoli_directory_server | 6.2.0.40 |
| ibm | tivoli_directory_server | 6.1.0.37 |
| ibm | tivoli_directory_server | 6.1.0.15 |
| ibm | tivoli_directory_server | 6.2.0.4 |
| ibm | tivoli_directory_server | 6.3.0.39 |
| ibm | tivoli_directory_server | 6.1.0.0 |
| ibm | tivoli_directory_server | 6.3.0.14 |
| ibm | tivoli_directory_server | 6.3.0.41 |
| ibm | tivoli_directory_server | 6.2.0.37 |
| ibm | tivoli_directory_server | 6.1.0.39 |
| ibm | tivoli_directory_server | 6.2.0.14 |
| ibm | tivoli_directory_server | 6.1.0.60 |
| ibm | security_directory_server | 6.3.1.3 |
| ibm | tivoli_directory_server | 6.1.0.5 |
| ibm | tivoli_directory_server | 6.1.0.64 |
| ibm | security_directory_server | 6.4.0.3 |
| ibm | tivoli_directory_server | 6.1.0.43 |
| ibm | tivoli_directory_server | 6.1.0.65 |
| ibm | tivoli_directory_server | 6.3.0.28 |
| ibm | tivoli_directory_server | 6.1.0.11 |
| ibm | tivoli_directory_server | 6.1.0.48 |
| ibm | tivoli_directory_server | 6.3.0.29 |
| ibm | tivoli_directory_server | 6.1.0.25 |
| ibm | tivoli_directory_server | 6.1.0.56 |
| ibm | tivoli_directory_server | 6.2.0.39 |
| ibm | security_directory_server | 6.3.1.12 |
| ibm | tivoli_directory_server | 6.1.0.21 |
| ibm | security_directory_server | 6.3.1.2 |
| ibm | tivoli_directory_server | 6.3.0.42 |
| ibm | tivoli_directory_server | 6.1.0.26 |
| ibm | tivoli_directory_server | 6.2.0.3 |
| ibm | tivoli_directory_server | 6.1.0.32 |
| ibm | tivoli_directory_server | 6.1.0.46 |
| ibm | tivoli_directory_server | 6.1.0.1 |
| ibm | security_directory_server | 6.3.1.6 |
| ibm | tivoli_directory_server | 6.1.0.17 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | case_manager | 5.2.1 |
| ibm | case_manager | 5.2.1.1 |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_build | 6.1.0.1 |
| ibm | urbancode_build | 6.1.0.0 |
| ibm | urbancode_build | 6.1.0.2 |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance_m2000 | * |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.3.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_virtual_environments | * |
| ibm | tivoli_storage_flashcopy_manager | * |
SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, 6.3.2.x, 6.3.3.x, 6.3.5.0, and 6.3.6.0 improperly processes events, which allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | systems_director | 6.3.2.0 |
| ibm | systems_director | 6.3.1.1 |
| ibm | systems_director | 6.3.3.0 |
| ibm | systems_director | 6.3.5.0 |
| ibm | systems_director | 6.3.0.0 |
| ibm | systems_director | 6.3.1.0 |
| ibm | systems_director | 6.3.2.1 |
| ibm | systems_director | 5.20 |
| ibm | systems_director | 6.3.6.0 |
| ibm | systems_director | 6.3.3.1 |
| ibm | systems_director | 6.3.2.2 |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.1.0.3 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.1.0.5 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.1.0.4 |
| ibm | websphere_mq | 7.1.0.6 |
| ibm | websphere_mq | 7.5.0.5 |
| ibm | websphere_mq | 8.0 |
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 7.0.1.12 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.10 |
| ibm | websphere_mq | 7.0.1.11 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.9 |
| ibm | websphere_mq | 7.0.1.6 |
Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via a crafted URL, aka SPR SJAR9DNGDA.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
Cross-site scripting (XSS) vulnerability in pubnames.ntf (aka the Directory template) in the web server in IBM Domino before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH8WBPRN.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | * |
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 6.1.0.2 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 6.1.0.14 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 6.1.0.7 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 6.1.0.12 |
| ibm | websphere_application_server | 6.1.0.35 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 6.1.0.39 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 6.1.0.37 |
| ibm | websphere_application_server | 6.1.0.31 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 6.1.0.47 |
| ibm | websphere_application_server | 6.1.0.5 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 6.1.0.27 |
| ibm | websphere_application_server | 6.1.0.45 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 6.1.0.13 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 6.1.0 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 6.1 |
| ibm | websphere_application_server | 6.1.0.23 |
| ibm | websphere_application_server | 6.1.0.25 |
| ibm | websphere_application_server | 6.1.0.1 |
| ibm | websphere_application_server | 6.1.0.41 |
| ibm | websphere_application_server | 6.1.0.11 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 6.1.0.9 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 6.1.0.21 |
| ibm | websphere_application_server | 6.1.0.33 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 6.1.0.0 |
| ibm | websphere_application_server | 6.1.0.3 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 6.1.0.29 |
| ibm | websphere_application_server | 6.1.0.43 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 6.1.0.17 |
| ibm | websphere_application_server | 6.1.0.15 |
| ibm | websphere_application_server | 6.1.0.19 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.6 |
| ibm | websphere_message_broker | 7.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | integration_bus | 10.0 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | websphere_message_broker | 7.0. |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.7 |
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_directory_server | 6.3.0.0 |
| ibm | tivoli_directory_server | 6.1.0 |
| ibm | tivoli_directory_server | 6.3.1.0 |
| ibm | tivoli_directory_server | 6.4.0 |
| ibm | tivoli_directory_server | 6.0 |
| ibm | tivoli_directory_server | 6.2.0.0 |
Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | 7.1 |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N | 2.2 | 1.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | http_server | 12.1.3.0.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| suse | linux_enterprise_software_development_kit | 12 |
| suse | linux_enterprise_desktop | 12 |
| redhat | enterprise_linux_server_aus | 7.7 |
| huawei | 9700_firmware | - |
| huawei | s5700ei_firmware | - |
| debian | debian_linux | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| huawei | smc2.0 | v100r002c03 |
| redhat | enterprise_linux_eus | 7.1 |
| huawei | s5700hi_firmware | - |
| huawei | te60_firmware | - |
| redhat | enterprise_linux_eus | 7.3 |
| huawei | oceanstor_9000_firmware | - |
| canonical | ubuntu_linux | 15.04 |
| suse | linux_enterprise_server | 10 |
| huawei | s5700si_firmware | - |
| redhat | enterprise_linux_desktop | 6.0 |
| oracle | integrated_lights_out_manager_firmware | * |
| redhat | enterprise_linux_server_aus | 7.3 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_server_tus | 7.7 |
| huawei | oceanstor_vis6600t_firmware | - |
| fujitsu | sparc_enterprise_m5000_firmware | * |
| redhat | enterprise_linux_workstation | 5.0 |
| huawei | oceanstor_hvs85t_firmware | - |
| redhat | satellite | 5.6 |
| ibm | cognos_metrics_manager | 10.2 |
| huawei | oceanstor_18800_firmware | - |
| huawei | e6000_firmware | - |
| huawei | smc2.0 | v100r002c02 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_eus | 7.2 |
| redhat | enterprise_linux_eus | 6.6 |
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| huawei | oceanstor_cse_firmware | - |
| huawei | s3700_firmware | - |
| fujitsu | sparc_enterprise_m4000_firmware | * |
| redhat | enterprise_linux_eus | 7.5 |
| oracle | http_server | 11.1.1.9.0 |
| huawei | oceanstor_18800f_firmware | - |
| redhat | enterprise_linux_server_aus | 7.4 |
| huawei | oceanstor_s2600t_firmware | - |
| redhat | enterprise_linux_server_tus | 7.6 |
| huawei | s2700_firmware | - |
| suse | linux_enterprise_debuginfo | 11 |
| suse | linux_enterprise_desktop | 11 |
| ibm | cognos_metrics_manager | 10.1.1 |
| huawei | s2750_firmware | - |
| huawei | oceanstor_18500_firmware | - |
| huawei | e9000_firmware | - |
| redhat | enterprise_linux_server_tus | 7.3 |
| suse | manager | 1.7 |
| opensuse | opensuse | 13.2 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_server | 7.0 |
| huawei | s5700li_firmware | - |
| redhat | enterprise_linux_server_aus | 6.6 |
| huawei | policy_center | v100r003c10 |
| huawei | ultravr | v100r003c00 |
| huawei | oceanstor_s5500t_firmware | - |
| oracle | http_server | 11.1.1.7.0 |
| suse | linux_enterprise_server | 12 |
| ibm | cognos_metrics_manager | 10.1 |
| ibm | cognos_metrics_manager | 10.2.1 |
| huawei | oceanstor_s5600t_firmware | - |
| ibm | cognos_metrics_manager | 10.2.2 |
| redhat | enterprise_linux_eus | 7.6 |
| huawei | s6700_firmware | - |
| debian | debian_linux | 8.0 |
| opensuse | opensuse | 13.1 |
| huawei | s5700s-li_firmware | - |
| redhat | enterprise_linux_eus | 7.4 |
| suse | linux_enterprise_software_development_kit | 11 |
| huawei | oceanstor_s5800t_firmware | - |
| huawei | policy_center | v100r003c00 |
| oracle | communications_policy_management | * |
| huawei | s12700_firmware | - |
| huawei | smc2.0 | v100r002c04 |
| huawei | s5720ei_firmware | - |
| redhat | enterprise_linux_server | 6.0 |
| huawei | smc2.0 | v100r002c01 |
| oracle | communications_application_session_controller | * |
| huawei | s5710hi_firmware | - |
| huawei | oceanstor_replicationdirector | v100r003c00 |
| oracle | http_server | 12.2.1.1.0 |
| oracle | http_server | 12.2.1.2.0 |
| fujitsu | sparc_enterprise_m8000_firmware | * |
| huawei | s5710ei_firmware | - |
| redhat | enterprise_linux_desktop | 5.0 |
| huawei | oceanstor_s6800t_firmware | - |
| fujitsu | sparc_enterprise_m3000_firmware | * |
| huawei | s7700_firmware | - |
| huawei | s5720hi_firmware | - |
| fujitsu | sparc_enterprise_m9000_firmware | * |
| huawei | quidway_s9300_firmware | - |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server_aus | 7.6 |
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pcre | pcre | 8.33 |
| pcre | pcre | 8.37 |
| ibm | powerkvm | 3.1 |
| pcre | pcre2 | 10.10 |
| pcre | pcre | 8.34 |
| pcre | pcre | 7.8 |
| pcre | pcre | 8.36 |
| pcre | pcre | 8.32 |
| pcre | pcre | 8.35 |
| ibm | powerkvm | 2.1 |
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N | 2.2 | 1.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | - |
| debian | debian_linux | 8.0 |
| mozilla | seamonkey | 2.35 |
| oracle | jre | 1.7.0 |
| oracle | jdk | 1.8.0 |
| opera | opera_browser | - |
| mozilla | firefox | - |
| suse | linux_enterprise_software_development_kit | 12 |
| oracle | jdk | 1.6.0 |
| suse | linux_enterprise_desktop | 12 |
| canonical | ubuntu_linux | 14.10 |
| debian | debian_linux | 7.0 |
| mozilla | thunderbird | 31.8 |
| mozilla | firefox | 38.1.0 |
| suse | suse_linux_enterprise_server | 12 |
| mozilla | firefox_esr | 31.8 |
| apple | safari | - |
| oracle | jre | 1.6.0 |
| apple | mac_os_x | * |
| mozilla | firefox | 39.0 |
| canonical | ubuntu_linux | 15.04 |
| ibm | content_manager | 8.5 |
| oracle | jdk | 1.7.0 |
| openssl | openssl | * |
| canonical | ubuntu_linux | 12.04 |
| apple | iphone_os | * |
| mozilla | firefox_os | 2.2 |
| oracle | sparc-opl_service_processor | * |
| oracle | jre | 1.8.0 |
| canonical | ubuntu_linux | 14.04 |
| oracle | jrockit | r28.3.6 |
| mozilla | thunderbird | 38.1 |
| hp | hp-ux | b.11.31 |
| suse | linux_enterprise_server | 11.0 |
| chrome | - | |
| mozilla | network_security_services | 3.19 |
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 7.1.2 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | license_metric_tool | 9.0 |
| ibm | license_metric_tool | 9.1.0.1 |
| ibm | license_metric_tool | 9.0.1 |
| ibm | license_metric_tool | 9.1.0.2 |
IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4932, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4935.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4934.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0.1 |
| ibm | websphere_extreme_scale | 8.6.0.5 |
| ibm | websphere_extreme_scale | 8.6.0.7 |
| ibm | websphere_extreme_scale | 8.6.0.8 |
| ibm | websphere_extreme_scale | 8.6.0.4 |
| ibm | websphere_extreme_scale | 8.6.0.6 |
| ibm | websphere_extreme_scale | 8.6.0.3 |
| ibm | websphere_extreme_scale | 8.6.0.2 |
| ibm | websphere_extreme_scale | 8.6.0.0 |
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_program_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_program_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_program_management | 10.0.1.1 |
| ibm | emptoris_program_management | 10.0.2.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.0 |
| ibm | emptoris_program_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_program_management | 10.0.2.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.2 |
| ibm | emptoris_program_management | 10.0.0.2 |
| ibm | emptoris_program_management | 10.0.0.3 |
| ibm | emptoris_program_management | 10.0.1.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_program_management | 10.0.2.0 |
| ibm | emptoris_program_management | 10.0.1.0 |
| ibm | emptoris_program_management | 10.0.1.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.2 |
| ibm | emptoris_program_management | 10.0.2.7 |
| ibm | emptoris_program_management | 10.0.0.0 |
| ibm | emptoris_program_management | 10.0.1.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_program_management | 10.0.2.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.5 |
IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4942.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_light | 1.0.0.1 |
| ibm | websphere_mq_light | 1.0 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_anywhere | 7.5.1.0 |
| ibm | maximo_anywhere | 7.5.1.1 |
| ibm | maximo_anywhere | 7.5.1.2 |
Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Engineering Lifecycle Manager (RELM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; Rational Rhapsody Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; and Rational Software Architect Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1 allows local users to bypass intended access restrictions via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | http_server | * |
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 2.2.0 |
| ibm | vios | 2.2.1 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.3 |
| ibm | vios | 2.2.2 |
| ibm | aix | 7.1 |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage FlashCopy Manager 4.1 before 4.1.2 place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading GUI pop-up windows, a different vulnerability than CVE-2015-6557.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.2 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.2 |
The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1; and Tivoli Storage Manager FastBack for Microsoft Exchange 6.1 before 6.1.5.4 does not ensure that the correct mailbox is selected, which allows remote authenticated users to obtain sensitive information via a duplicate alias name.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4 |
| ibm | tivoli_storage_flashcopy_manager_for_microsoft_exchange_server | 2.2 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.1 |
| ibm | tivoli_storage_flashcopy_manager_for_microsoft_exchange_server | 4.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1 |
| ibm | tivoli_storage_fastback_for_microsoft_exchange | 6.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3 |
| ibm | tivoli_storage_flashcopy_manager_for_microsoft_exchange_server | 3.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.2 |
| ibm | tivoli_storage_flashcopy_manager_for_microsoft_exchange_server | 2.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.3 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4.1 |
| ibm | tivoli_storage_flashcopy_manager_for_microsoft_exchange_server | 3.2 |
Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted Web client URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.2 |
| ibm | tivoli_storage_manager | 5.5 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.4 |
The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | endpoint_manager_for_remote_control | 9.1.0 |
| ibm | endpoint_manager_for_remote_control | 9.0.1 |
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | 9.1.2 |
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | 9.1.2 |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP16 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.2 |
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Engineering Lifecycle Manager (RELM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; Rational Rhapsody Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; and Rational Software Architect Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1 uses weak permissions for unspecified project areas, which allows remote authenticated users to obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_requirements_composer | 2.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_team_concert | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_team_concert | 2.0.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_requirements_composer | 2.0.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_requirements_composer | 2.0.0.2 |
| ibm | rational_quality_manager | 2.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0.0.1 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_software_architect_design_manager | 3.0.0.1 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_software_architect_design_manager | 3.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 1.0 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_requirements_composer | 2.0.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_software_architect_design_manager | 3.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_team_concert | 2.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_requirements_composer | 2.0.0.4 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_rhapsody_design_manager | 3.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web | 7.0.0.9 |
| ibm | security_access_manager_for_web | 7.0.0.15 |
| ibm | security_access_manager_for_web | 7.0.0.7 |
| ibm | security_access_manager_for_web | 8.0.0.2 |
| ibm | security_access_manager_for_web | 8.0.1.0 |
| ibm | security_access_manager_for_web | 7.0.0.8 |
| ibm | security_access_manager_for_web | 8.0.0.31 |
| ibm | security_access_manager_for_web | 7.0 |
| ibm | security_access_manager_for_web | 8.0.0.4 |
| ibm | security_access_manager_for_web | 7.0.0.5 |
| ibm | security_access_manager_for_web | 7.0.0.6 |
| ibm | security_access_manager_for_web | 8.0.0.5 |
| ibm | security_access_manager_for_web | 7.0.0.14 |
| ibm | security_access_manager_for_web | 7.0.0.13 |
| ibm | security_access_manager_for_web | 8.0.0.22 |
| ibm | security_access_manager_for_web | 8.0.1.2 |
| ibm | security_access_manager_for_web | 7.0.0.10 |
| ibm | security_access_manager_for_web | 7.0.0.3 |
| ibm | security_access_manager_for_web | 8.0.1.1 |
| ibm | security_access_manager_for_web | 7.0.0.2 |
| ibm | security_access_manager_for_web | 7.0.0.4 |
| ibm | security_access_manager_for_web | 7.0.0.1 |
| ibm | security_access_manager_for_web | 8.0.0.3 |
| ibm | security_access_manager_for_web | 7.0.0.12 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager_for_web | 7.0.0.11 |
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to obtain sensitive information by reading a (1) backup or (2) debug application file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products have a default administrator account, which makes it easier for remote authenticated users to obtain access via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_program_management | 10.0.2.4 |
| ibm | emptoris_program_management | 10.0.0.2 |
| ibm | emptoris_program_management | 10.0.0.3 |
| ibm | emptoris_program_management | 10.0.1.4 |
| ibm | emptoris_program_management | 10.0.2.1 |
| ibm | emptoris_program_management | 10.0.2.0 |
| ibm | emptoris_program_management | 10.0.1.0 |
| ibm | emptoris_program_management | 10.0.1.3 |
| ibm | emptoris_program_management | 10.0.2.5 |
| ibm | emptoris_program_management | 10.0.2.7 |
| ibm | emptoris_program_management | 10.0.0.0 |
| ibm | emptoris_program_management | 10.0.1.2 |
| ibm | emptoris_program_management | 10.0.0.1 |
| ibm | emptoris_program_management | 10.0.1.1 |
| ibm | emptoris_program_management | 10.0.2.2 |
| ibm | emptoris_program_management | 10.0.2.3 |
| ibm | emptoris | strategic_supply_management |
| ibm | emptoris | supplier_lifecycle_management |
| ibm | emptoris_program_management | 10.0.2.6 |
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | b2b_advanced_communications | 1.0.0.2 |
| ibm | b2b_advanced_communications | 1.0.0.1 |
| ibm | b2b_advanced_communications | 1.0.0.3 |
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5.0.0 |
| ibm | general_parallel_file_system | 3.5.0.20 |
| ibm | general_parallel_file_system | 3.5.0.19 |
| ibm | general_parallel_file_system | 3.5.0.22 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 3.5.0.14 |
| ibm | general_parallel_file_system | 3.5.0.24 |
| ibm | general_parallel_file_system | 3.5.0.10 |
| ibm | general_parallel_file_system | 3.5.0.21 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | general_parallel_file_system | 3.5.0.4 |
| ibm | general_parallel_file_system | 3.5.0.16 |
| ibm | general_parallel_file_system | 3.5.0.15 |
| ibm | general_parallel_file_system | 3.5.0.2 |
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | general_parallel_file_system | 3.5.0.17 |
| ibm | general_parallel_file_system | 3.5.0.12 |
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 3.5.0.25 |
| ibm | general_parallel_file_system | 3.5.0.6 |
| ibm | general_parallel_file_system | 3.5.0.13 |
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | general_parallel_file_system | 3.5.0.8 |
| ibm | general_parallel_file_system | 3.5.0.23 |
| ibm | general_parallel_file_system | 3.5.0.26 |
| ibm | general_parallel_file_system | 3.5.0.18 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | general_parallel_file_system | 3.5.0.7 |
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.8 |
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5.0.0 |
| ibm | general_parallel_file_system | 3.5.0.20 |
| ibm | general_parallel_file_system | 3.5.0.19 |
| ibm | general_parallel_file_system | 3.5.0.22 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 3.5.0.14 |
| ibm | general_parallel_file_system | 3.5.0.24 |
| ibm | general_parallel_file_system | 3.5.0.10 |
| ibm | general_parallel_file_system | 3.5.0.21 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | general_parallel_file_system | 3.5.0.4 |
| ibm | general_parallel_file_system | 3.5.0.16 |
| ibm | general_parallel_file_system | 3.5.0.15 |
| ibm | general_parallel_file_system | 3.5.0.2 |
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | general_parallel_file_system | 3.5.0.17 |
| ibm | general_parallel_file_system | 3.5.0.12 |
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 3.5.0.25 |
| ibm | general_parallel_file_system | 3.5.0.6 |
| ibm | general_parallel_file_system | 3.5.0.13 |
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | general_parallel_file_system | 3.5.0.8 |
| ibm | general_parallel_file_system | 3.5.0.23 |
| ibm | general_parallel_file_system | 3.5.0.26 |
| ibm | general_parallel_file_system | 3.5.0.18 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | general_parallel_file_system | 3.5.0.7 |
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
Directory traversal vulnerability in the replay server in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary files via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
The portal in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows local users to discover credentials by leveraging privileges during an unspecified connection type.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_modeler | 14.2.0.1 |
| ibm | spss_modeler | 14.2.0.3 |
| ibm | spss_modeler | 16.0.0.0 |
| ibm | spss_modeler | 15.0.0.2 |
| ibm | spss_modeler | 17.0.0.1 |
| ibm | spss_modeler | 14.2.0.0 |
| ibm | spss_modeler | 17.1.0.0 |
| ibm | spss_modeler | 15.0.0.0 |
| ibm | spss_modeler | 15.0.0.1 |
| ibm | spss_modeler | 16.0.0.2 |
| ibm | spss_modeler | 17.0.0.0 |
| ibm | spss_modeler | 15.0.0.3 |
| ibm | spss_modeler | 14.2.0.2 |
| ibm | spss_modeler | 16.0.0.1 |
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash) via a crafted GIF image, aka SPRs KLYH9ZDKRE and KLYH9ZTLEZ, a different vulnerability than CVE-2015-5040.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.2 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3 |
IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover credentials via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | 8.0.0.12 |
| ibm | rational_clearquest | 8.0.0.5 |
| ibm | rational_clearquest | 8.0.1.2 |
| ibm | rational_clearquest | 8.0.0.15 |
| ibm | rational_clearquest | 7.1.1.1 |
| ibm | rational_clearquest | 7.1.2.2 |
| ibm | rational_clearquest | 8.0.1.1 |
| ibm | rational_clearquest | 7.1.1.3 |
| ibm | rational_clearquest | 8.0.0.1 |
| ibm | rational_clearquest | 8.0.0.3 |
| ibm | rational_clearquest | 7.1 |
| ibm | rational_clearquest | 8.0.0.9 |
| ibm | rational_clearquest | 8.0.0.11 |
| ibm | rational_clearquest | 7.1.1.5 |
| ibm | rational_clearquest | 8.0.0 |
| ibm | rational_clearquest | 8.0.0.2 |
| ibm | rational_clearquest | 8.0.0.14 |
| ibm | rational_clearquest | 8.0.1.7 |
| ibm | rational_clearquest | 7.1.1.4 |
| ibm | rational_clearquest | 7.1.2.11 |
| ibm | rational_clearquest | 7.1.2.12 |
| ibm | rational_clearquest | 7.1.0.1 |
| ibm | rational_clearquest | 8.0.0.13 |
| ibm | rational_clearquest | 8.0.1.8 |
| ibm | rational_clearquest | 7.1.1.7 |
| ibm | rational_clearquest | 7.1.1 |
| ibm | rational_clearquest | 7.1.2 |
| ibm | rational_clearquest | 7.1.0.2 |
| ibm | rational_clearquest | 8.0.0.7 |
| ibm | rational_clearquest | 8.0.0.10 |
| ibm | rational_clearquest | 8.0.1.9 |
| ibm | rational_clearquest | 8.0.0.16 |
| ibm | rational_clearquest | 8.0.1.3 |
| ibm | rational_clearquest | 8.0.1.5 |
| ibm | rational_clearquest | 8.0.1 |
| ibm | rational_clearquest | 8.0.1.4 |
| ibm | rational_clearquest | 7.1.2.7 |
| ibm | rational_clearquest | 7.1.2.1 |
| ibm | rational_clearquest | 7.1.1.9 |
| ibm | rational_clearquest | 7.1.2.3 |
| ibm | rational_clearquest | 8.0.0.8 |
| ibm | rational_clearquest | 8.0.0.4 |
| ibm | rational_clearquest | 7.1.2.5 |
| ibm | rational_clearquest | 7.1.1.8 |
| ibm | rational_clearquest | 7.1.2.6 |
| ibm | rational_clearquest | 7.1.2.8 |
| ibm | rational_clearquest | 7.1.1.6 |
| ibm | rational_clearquest | 7.1.2.9 |
| ibm | rational_clearquest | 7.1.2.10 |
| ibm | rational_clearquest | 7.1.1.2 |
| ibm | rational_clearquest | 7.1.2.4 |
| ibm | rational_clearquest | 8.0.0.6 |
IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | host_on-demand | 11.0.9 |
| ibm | host_on-demand | 11.0.4 |
| ibm | host_on-demand | 11.0.7 |
| ibm | host_on-demand | 11.0.1 |
| ibm | host_on-demand | 11.0.3 |
| ibm | host_on-demand | 11.0.12 |
| ibm | host_on-demand | 11.0 |
| ibm | host_on-demand | 11.0.13 |
| ibm | host_on-demand | 11.0.6 |
| ibm | host_on-demand | 11.0.2 |
| ibm | host_on-demand | 11.0.5 |
| ibm | host_on-demand | 11.0.11 |
| ibm | host_on-demand | 11.0.8 |
| ibm | host_on-demand | 11.0.10 |
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.3.0 |
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.0.0.2 |
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powerha_system_mirror | * |
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | satellite | 5.6 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| suse | linux_enterprise_software_development_kit | 11 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| suse | linux_enterprise_software_development_kit | 12 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_server_eus | 7.4 |
| ibm | java_sdk | * |
| redhat | satellite | 5.7 |
| suse | linux_enterprise_server | 12 |
| ibm | java_2_sdk | * |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server | 5.0 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.18 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.19 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.17 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.20 |
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
CVSS 2.0
Severity: LOW
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.4 |
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.18 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.17 |
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_disclosure_management | 10.2.4 |
| ibm | cognos_disclosure_management | 10.2.3 |
| ibm | cognos_disclosure_management | 10.2.1 |
| ibm | cognos_disclosure_management | 10.2.2 |
| ibm | cognos_disclosure_management | 10.2.0 |
IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce_enterprise | * |
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.6 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_for_government | 7.5 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | control_desk | 7.5 |
| ibm | control_desk | 7.6 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_for_transportation | 7.6 |
| ibm | maximo_for_aviation | 7.6 |
| ibm | maximo_for_oil_and_gas | 7.5 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended access restrictions and establish a login session by entering an expired password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.6 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_for_government | 7.5 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | tivoli_service_request_manager | 7.1 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_for_oil_and_gas | 7.5 |
IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_integrator | 5.1 |
The Big SQL component in IBM InfoSphere BigInsights 3.0, 3.0.0.1, 3.0.0.2, and 4.0 allows remote authenticated users to bypass intended access restrictions and truncate arbitrary tables via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 3.0.0.1 |
| ibm | infosphere_biginsights | 4.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.0 |
| ibm | infosphere_biginsights | 3.0.0.2 |
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | b2b_advanced_communications | 1.0.0.2 |
| ibm | b2b_advanced_communications | 1.0.0.1 |
| ibm | b2b_advanced_communications | 1.0.0.3 |
SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.2 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.1 |
| ibm | curam_social_program_management | 6.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4 |
| ibm | curam_social_program_management | 6.0.1 |
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.2.0 |
| ibm | emptoris_sourcing | 10.0.2.3 |
| ibm | emptoris_sourcing | 10.0.4.0 |
| ibm | emptoris_sourcing | 10.0.2.7 |
| ibm | emptoris_sourcing | 10.0.2.2 |
| ibm | emptoris_sourcing | 10.0.2.6 |
| ibm | emptoris_sourcing | 10.0.2.5 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5036.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | * |
| ibm | connections | 4.0 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-5035.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | * |
| ibm | connections | 4.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | * |
| ibm | connections | 4.0 |
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | * |
| ibm | connections | 4.0 |
The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate. IBM X-Force ID: 106715.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | * |
Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash) via a crafted GIF image, aka SPRs KLYH9ZDKRE and KLYH9ZTLEZ, a different vulnerability than CVE-2015-4994.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 8.5.0.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.2.3 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 8.5.2.4 |
| ibm | domino | 8.5.1.3 |
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_server | 12 |
| redhat | satellite | 5.6 |
| suse | suse_linux_enterprise_server | 12 |
| ibm | websphere_application_server | * |
| suse | linux_enterprise_software_development_kit | 11 |
| suse | linux_enterprise_software_development_kit | 12 |
| ibm | java_sdk | * |
| redhat | satellite | 5.7 |
IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers to execute arbitrary code by including a crafted Flash file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_contract_management | 10.0.2.4 |
| ibm | emptoris_contract_management | 10.0.2.5 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 10.0.2.3 |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_contract_management | 10.0.4.0 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.2.7 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_contract_management | 10.0.2.6 |
| ibm | emptoris_contract_management | 9.5.0.6 |
diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 8.2 |
| ibm | security_guardium | 9.5 |
The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.0.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.0.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors. IBM X-Force ID: 106938.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_license_key_server | 8.1.4.5 |
| ibm | rational_license_key_server | 8.1.4.9 |
| ibm | rational_license_key_server | 8.1.4 |
| ibm | rational_license_key_server | 8.1.4.4 |
| ibm | rational_license_key_server | 8.1.4.3 |
| ibm | rational_license_key_server | 8.1.4.6 |
| ibm | rational_license_key_server | 8.1.4.7 |
| ibm | rational_license_key_server | 8.1.4.2 |
| ibm | rational_license_key_server | 8.1.4.8 |
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.0.0.3 |
| ibm | openpages_grc_platform | 7.0.0.2 |
| ibm | openpages_grc_platform | 7.0.0.0 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.0.0.1 |
| ibm | openpages_grc_platform | 7.0.0.4 |
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_contract_management | 10.0.2.4 |
| ibm | emptoris_contract_management | 10.0.2.5 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 10.0.2.3 |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_contract_management | 10.0.4.0 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.2.7 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_contract_management | 10.0.2.6 |
| ibm | emptoris_contract_management | 9.5.0.6 |
IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow remote authenticated users to bypass intended access restrictions on query results via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_government | 7.5 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_asset_management_essentials | 7.6 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5 |
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pcre | pcre | * |
| ibm | powerkvm | 3.1 |
| ibm | powerkvm | 2.1 |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.5 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.1 |
| ibm | tivoli_storage_flashcopy_manager | 3.2.0 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.2 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 5.5 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.3 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.4 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.0 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.6 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.2 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 5.5.1 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5 |
| ibm | tivoli_storage_flashcopy_manager | 3.2.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.3 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended work-order change restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.5.0.4 |
| ibm | tivoli_service_request_manager | 7.2.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_for_nuclear_power | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_oil_and_gas | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.5 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | maximo_for_life_sciences | 7.5.0.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.1 |
| ibm | maximo_for_utilities | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.2 |
| ibm | maximo_for_nuclear_power | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.4 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_government | 7.5.0.6 |
| ibm | maximo_for_utilities | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_nuclear_power | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_for_life_sciences | 7.5.0.0 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.3 |
| ibm | maximo_for_government | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_life_sciences | 7.5.0.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_for_government | 7.5.0.2 |
| ibm | maximo_for_oil_and_gas | 7.5.0.1 |
| ibm | maximo_for_nuclear_power | 7.5.0.2 |
| ibm | maximo_for_utilities | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_government | 7.5.0.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_utilities | 7.5.0.6 |
| ibm | maximo_for_transportation | 7.5.0.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_life_sciences | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_for_transportation | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | maximo_for_government | 7.5.0.3 |
| ibm | maximo_for_utilities | 7.5.0.4 |
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_government | 7.5 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5 |
Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 9.5.0.1 |
| ibm | emptoris_contract_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 9.5.0.4 |
| ibm | emptoris_contract_management | 10.0.2.4 |
| ibm | emptoris_contract_management | 10.0.2.5 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 9.5.0.3 |
| ibm | emptoris_contract_management | 9.5.0.0 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 10.0.2.3 |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_contract_management | 10.0.4.0 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 9.5.0.5 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.2.7 |
| ibm | emptoris_contract_management | 9.5.0.2 |
| ibm | emptoris_contract_management | 10.0.2.6 |
| ibm | emptoris_contract_management | 9.5.0.6 |
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 7.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.2 |
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 7.0.0.5 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.4 |
| ibm | websphere_message_broker | 7.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | websphere_message_broker | 7.0.0.3 |
| ibm | integration_bus | 10.0 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | websphere_message_broker | 7.0. |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 7.0.0.7 |
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mashups_center | 3.0.0.1 |
IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id. IBM X-Force ID: 107106.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | * |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1 |
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | general_parallel_file_system | 3.5 |
| ibm | spectrum_scale | 4.1.1.1 |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5 before 5.5.1.1, 6.1 and 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; and Tivoli Storage FlashCopy Manager for Windows (aka Spectrum Protect Snapshot) 2.x and 3.1 before 3.1.1.6, 3.2 before 3.2.1.8, and 4.1 before 4.1.4, when application tracing is configured, write cleartext passwords during changetsmpassword command execution, which allows local users to obtain sensitive information by reading the application trace output.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1.2.1 |
| ibm | tivoli_storage_flashcopy_manager | 3.2.0 |
| ibm | tivoli_storage_flashcopy_manager | 2.1.0 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1.3 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.0.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1.1.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.2 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1.3 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1.0.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3 |
| ibm | tivoli_storage_flashcopy_manager | 3.1.0 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1.5 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.2 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 5.5.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.5 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.3.1 |
| ibm | tivoli_storage_flashcopy_manager | 2.2.1 |
| ibm | tivoli_storage_flashcopy_manager | 6.1.3 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1.3 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.3.0 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1.7 |
| ibm | tivoli_storage_flashcopy_manager | 2.2.0 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 5.5 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.4 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.0.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 6.4 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.3.1.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.6 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.0.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1.4 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 6.4.1.2 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 7.1.0.1 |
| ibm | tivoli_storage_flashcopy_manager | 3.2.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.2.0 |
| ibm | tivoli_storage_flashcopy_manager | 4.1.0.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.2.1 |
| ibm | tivoli_storage_manager_for_mail_data_protection_for_microsoft_exchange_server | 7.1.0.1 |
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | 5.5.3 |
Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mashups_center | 3.0.0.1 |
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3.5.0 |
| ibm | tivoli_storage_manager | 6.3.4.0 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 5.5.0.0 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 6.2.0.0 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.1.0.0 |
| ibm | tivoli_storage_manager | 6.3.3.0 |
| ibm | tivoli_storage_manager | 7.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM UrbanCode Deploy 6.0 before 6.0.1.12, 6.1 before 6.1.3.2, and 6.2 before 6.2.0.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | 7.1 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.5 |
| ibm | websphere_extreme_scale | 8.6 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.5.0.0 |
Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7421.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance_m2000 | * |
Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7420.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance_m2000 | * |
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | 7.1 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 9.1 |
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.3 |
| ibm | infosphere_master_data_management | 11.5 |
The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.4 allows remote attackers to obtain administrative privileges via a crafted URL that triggers back-end function execution.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 6.4 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 4.1.1 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 4.1.3 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.0 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 6.4.3 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 3.1 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.1 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 3.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.3 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 4.1.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 4.1.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 6.3.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 6.4.1 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 3.1.1 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 6.3 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 6.4.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 6.3.1 |
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_for_virtual_environments | 7.1 |
| ibm | spectrum_protect_snapshot | 4.1 |
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | 7.2.0.0 |
| ibm | datapower_gateway | 6.0.1.14 |
| ibm | datapower_gateway | 6.0.1.1 |
| ibm | datapower_gateway | 7.1.0.6 |
| ibm | datapower_gateway | 7.0.0.0 |
| ibm | datapower_gateway | 7.0.0.4 |
| ibm | datapower_gateway | 6.0.1.16 |
| ibm | datapower_gateway | 7.0.0.8 |
| ibm | datapower_gateway | 6.0.1.2 |
| ibm | datapower_gateway | 6.0.1.3 |
| ibm | datapower_gateway | 7.0.0.9 |
| ibm | datapower_gateway | 6.0.1.9 |
| ibm | datapower_gateway | 7.0.0.2 |
| ibm | datapower_gateway | 6.0.1.8 |
| ibm | datapower_gateway | 7.1.0.4 |
| ibm | datapower_gateway | 6.0.1.7 |
| ibm | datapower_gateway | * |
| ibm | datapower_gateway | 7.0.0.5 |
| ibm | datapower_gateway | 7.1.0.1 |
| ibm | datapower_gateway | 6.0.1.0 |
| ibm | datapower_gateway | 6.0.1.11 |
| ibm | datapower_gateway | 6.0.1.12 |
| ibm | datapower_gateway | 7.0.0.6 |
| ibm | datapower_gateway | 6.0.1.13 |
| ibm | datapower_gateway | 7.1.0.2 |
| ibm | datapower_gateway | 6.0.1.4 |
| ibm | datapower_gateway | 6.0.1.6 |
| ibm | datapower_gateway | 7.1.0.0 |
| ibm | datapower_gateway | 6.0.1.5 |
| ibm | datapower_gateway | 6.0.1.15 |
| ibm | datapower_gateway | 7.1.0.5 |
| ibm | datapower_gateway | 6.0.1.10 |
| ibm | datapower_gateway | 7.0.0.3 |
| ibm | datapower_gateway | 7.1.0.3 |
| ibm | datapower_gateway | 7.0.0.7 |
| ibm | datapower_gateway | 7.0.0.1 |
Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote authenticated users to restore arbitrary virtual machines and consequently obtain sensitive information by visiting the vSphere inventory.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_for_virtual_environments | 7.1 |
| ibm | spectrum_protect_snapshot | 4.1 |
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | capacity_management_analytics | 2.1.0.0 |
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | capacity_management_analytics | 2.1.0.0 |
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | capacity_management_analytics | 2.1.0.0 |
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 allows local users to bypass the Cognos Application Firewall (CAF) protection mechanism via leading whitespace in the BackURL field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_common_reporting | 3.1.2.1 |
| ibm | tivoli_common_reporting | 3.1.0.1 |
| ibm | tivoli_common_reporting | 2.1.1.2 |
| ibm | tivoli_common_reporting | 3.1.2 |
| ibm | tivoli_common_reporting | 2.1.1 |
| ibm | tivoli_common_reporting | 3.1.0.2 |
| ibm | tivoli_common_reporting | 3.1 |
| ibm | tivoli_common_reporting | 2.1 |
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 preserves user permissions across group-add and group-remove operations, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging administrative changes to group membership.
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_common_reporting | 3.1.2.1 |
| ibm | tivoli_common_reporting | 3.1.0.1 |
| ibm | tivoli_common_reporting | 2.1.1.2 |
| ibm | tivoli_common_reporting | 3.1.2 |
| ibm | tivoli_common_reporting | 2.1.1 |
| ibm | tivoli_common_reporting | 3.1.0.2 |
| ibm | tivoli_common_reporting | 3.1 |
| ibm | tivoli_common_reporting | 2.1 |
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Architect 8.5 through 9.5, Rational Software Architect for WebSphere Software (RSA4WS) 8.5 through 9.5, and Rational Software Architect RealTime (RSART) 8.5 through 9.5, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect | 8.5.5 |
| ibm | rational_software_architect_realtime | 9.0.0 |
| ibm | rational_software_architect_for_websphere_software | 9.1.2 |
| ibm | rational_software_architect_realtime | 8.5.0 |
| ibm | rational_software_architect_realtime | 8.5.1 |
| ibm | rational_software_architect_for_websphere_software | 8.5.5.4 |
| ibm | rational_software_architect | 9.1.1 |
| ibm | rational_software_architect_for_websphere_software | 9.1.1 |
| ibm | rational_software_architect_for_websphere_software' | 8.5.5.1 |
| ibm | rational_software_architect_realtime | 9.1.2 |
| ibm | rational_software_architect_realtime | 9.5.0 |
| ibm | rational_software_architect_realtime | 9.0.0.1 |
| ibm | rational_software_architect_realtime | 8.5.5 |
| ibm | rational_software_architect | 8.5.5.1 |
| ibm | rational_software_architect_realtime | 9.1.0 |
| ibm | rational_software_architect_for_websphere_software | 8.5.5 |
| ibm | rational_software_architect_for_websphere_software | 8.5.5.3 |
| ibm | rational_software_architect_for_websphere_software | 9.1.0 |
| ibm | rational_software_architect | 8.5.5.4 |
| ibm | rational_software_architect | 9.1.2 |
| ibm | rational_software_architect | 8.5.0 |
| ibm | rational_software_architect_realtime | 8.5.5.2 |
| ibm | rational_software_architect_realtime | 9.1.1 |
| ibm | rational_software_architect_for_websphere_software | 9.0.0 |
| ibm | rational_software_architect | 8.5.5.2 |
| ibm | rational_software_architect | 8.5.1.0 |
| ibm | rational_software_architect_for_websphere_software | 9.1.2.1 |
| ibm | rational_software_architect_realtime | 8.5.1.0 |
| ibm | rational_software_architect | 8.5.5.3 |
| ibm | rational_software_architect | 9.5.0 |
| ibm | rational_software_architect_realtime | 8.5.5.4 |
| ibm | rational_software_architect_for_websphere_software | 8.5.0 |
| ibm | rational_software_architect_for_websphere_software | 9.5.0 |
| ibm | rational_software_architect_for_websphere_software | 8.5.1 |
| ibm | rational_software_architect | 9.0.0.1 |
| ibm | rational_software_architect | 9.0.0 |
| ibm | rational_software_architect | 9.1.2.1 |
| ibm | rational_software_architect_for_websphere_software | 8.5.1.0 |
| ibm | rational_software_architect_realtime | 8.5.5.1 |
| ibm | rational_software_architect | 8.5.1 |
| ibm | rational_software_architect_realtime | 8.5.5.3 |
| ibm | rational_software_architect_for_websphere_software | 8.5.5.2 |
| ibm | rational_software_architect | 9.1.0 |
| ibm | rational_software_architect_for_websphere_software | 9.0.0.1 |
| ibm | rational_software_architect_realtime | 9.1.2.1 |
IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 might allow local users to gain privileges via unspecified vectors. IBM X-Force ID: 108098.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_requirements_composer | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-17,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | websphere_process_server | 7.0 |
| ibm | business_process_manager | 7.5.0.0 |
consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | installation_manager | 1.8.2.1 |
| ibm | packaging_utility | 1.8.2.0 |
| ibm | installation_manager | 1.8.2.0 |
| ibm | packaging_utility | 1.8.2.1 |
| ibm | packaging_utility | 1.8.0.0 |
| ibm | installation_manager | 1.8.1.0 |
| ibm | packaging_utility | * |
| ibm | installation_manager | 1.8.0.0 |
| ibm | installation_manager | 1.8.3.0 |
| ibm | packaging_utility | 1.8.3.0 |
| ibm | installation_manager | 1.7.4.3 |
| ibm | packaging_utility | 1.8.1.0 |
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.8 |
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | b2b_advanced_communications | 1.0.0.2 |
| ibm | b2b_advanced_communications | 1.0.0.1 |
| ibm | b2b_advanced_communications | 1.0 |
| ibm | b2b_advanced_communications | 1.0.0.3 |
| ibm | multi-enterprise_integration_gateway | 1.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flashsystem_v9000_firmware | 7.5 |
| ibm | flashsystem_v9000_firmware | 7.6 |
| ibm | flashsystem_v9000_firmware | 7.4 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF09 allows remote attackers to bypass intended Portal AccessControl REST API access restrictions and obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.7 |
| ibm | change_and_configuration_management_database | 7.2.1.3 |
| ibm | tivoli_asset_management_for_it | 7.2.2 |
| ibm | tivoli_service_request_manager | 7.1.0.3 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | tivoli_service_request_manager | 7.1.0.4 |
| ibm | change_and_configuration_management_database | 7.1.1.3 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_for_government | 7.5 |
| ibm | smartcloud_control_desk | 7.5.3 |
| ibm | maximo_for_nuclear_power | 7.5.0.1 |
| ibm | tivoli_service_request_manager | 7.2.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.2 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | change_and_configuration_management_database | 7.1.1.5 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | change_and_configuration_management_database | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | smartcloud_control_desk | 7.5.3.1 |
| ibm | smartcloud_control_desk | 7.5.1.1 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_for_oil_and_gas | 7.1.1.0 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | tivoli_service_request_manager | 7.2.1.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | tivoli_asset_management_for_it | 7.2.0.1 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_transportation | 7.6.0.0 |
| ibm | maximo_for_oil_and_gas | 7.5 |
| ibm | change_and_configuration_management_database | 7.2.0.2 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_for_transportation | 7.1.0.1 |
| ibm | change_and_configuration_management_database | 7.1.1.6 |
| ibm | maximo_for_nuclear_power | 7.5.1 |
| ibm | tivoli_service_request_manager | 7.2.1.2 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | change_and_configuration_management_database | 7.1.1.4 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | tivoli_service_request_manager | 7.1.0.1 |
| ibm | tivoli_service_request_manager | 7.2.1.6 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | tivoli_service_request_manager | 7.2.1.4 |
| ibm | maximo_asset_management_essentials | 7.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.9 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_for_government | 7.1.1 |
| ibm | smartcloud_control_desk | 7.5.0.1 |
| ibm | tivoli_asset_management_for_it | 7.2.1.0 |
| ibm | maximo_for_utilities | 7.5.0.1 |
| ibm | smartcloud_control_desk | 7.5.0.3 |
| ibm | tivoli_asset_management_for_it | 7.2.1.2 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_utilities | 7.1.1 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | change_and_configuration_management_database | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | tivoli_asset_management_for_it | 7.2.2.2 |
| ibm | smartcloud_control_desk | 7.5.1.3 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | change_and_configuration_management_database | 7.2.1.4 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | tivoli_service_request_manager | 7.1.0.5 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | smartcloud_control_desk | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | smartcloud_control_desk | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_for_utilities | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | change_and_configuration_management_database | 7.2.0.1 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_transportation | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_for_transportation | 7.5.0.0 |
| ibm | tivoli_service_request_manager | 7.2.0.1 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | change_and_configuration_management_database | 7.2.1.1 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.8 |
| ibm | tivoli_service_request_manager | 7.2.1.3 |
| ibm | tivoli_service_request_manager | 7.1.0.2 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_for_transportation | 7.1.1 |
| ibm | tivoli_asset_management_for_it | 7.2.2.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | tivoli_service_request_manager | 7.2.1.0 |
| ibm | maximo_for_transportation | 7.5.1.0 |
| ibm | maximo_for_oil_and_gas | 7.5.1 |
| ibm | change_and_configuration_management_database | 7.2.1 |
| ibm | change_and_configuration_management_database | 7.2.1.2 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_for_oil_and_gas | 7.1.2 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_for_nuclear_power | 7.1.1 |
| ibm | maximo_for_oil_and_gas | 7.1.0.1 |
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_requirements_composer | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-502,CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5 |
| ibm | tivoli_common_reporting | 3.1.2 |
| ibm | watson_explorer_analytical_components | 11.0 |
| ibm | tivoli_common_reporting | 2.1.1 |
| ibm | watson_content_analytics | * |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | tivoli_common_reporting | 3.1 |
| ibm | watson_explorer_annotation_administration_console | * |
| ibm | watson_explorer_annotation_administration_console | 11.0 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | tivoli_common_reporting | 2.1 |
| ibm | tivoli_common_reporting | 3.1.2.1 |
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_integrator | 5.1 |
| ibm | tivoli_common_reporting | 3.1.0.1 |
| ibm | tivoli_common_reporting | 2.1.1.2 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | tivoli_common_reporting | 3.1.0.2 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | watson_explorer_analytical_components | * |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_government | 7.5 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5 |
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_government | 7.5 |
| ibm | smartcloud_control_desk | 7.5 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_oil_and_gas | 7.5 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108296.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_requirements_composer | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_process_server | 6.1.2 |
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | websphere_process_server | 6.2.0.3 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere_process_server | 7.0.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_process_server | 7.0.0.2 |
| ibm | websphere_process_server | 7.0.0.3 |
| ibm | websphere_process_server | 6.2.0.2 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | websphere_process_server | 6.1.2.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | websphere_process_server | 6.2.0.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_process_server | 6.2 |
| ibm | websphere_process_server | 7.0.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | websphere_process_server | 6.1.2.3 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | websphere_process_server | 7.0.0.5 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | websphere_process_server | 7.0 |
| ibm | websphere_process_server | 6.1.2.1 |
| ibm | business_process_manager | 7.5.0.0 |
IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | spectrum_scale | 4.2.2.0 |
| ibm | spectrum_scale | 4.1.1.1 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108354.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | * |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | * |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108356.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | * |
| ibm | connections | 4.0.0.0 |
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | * |
| ibm | connections | 4.0.0.0 |
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.4 |
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-285,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder server outage) via a crafted request to a Report Builder instance URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote authenticated users with project administrator privileges to inject arbitrary web script or HTML via a crafted project. IBM X-Force ID: 108429.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_requirements_composer | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108501.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108626.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108633.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow local users to obtain sensitive information by leveraging administrative privileges and reading log files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | 7.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.7 |
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_for_government | 7.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | tivoli_service_request_manager | 7.2 |
| ibm | smartcloud_control_desk | 7.5.1.0 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_for_oil_and_gas | 7.5 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | smartcloud_control_desk | 7.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.6 |
| ibm | change_and_configuration_management_database | 7.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.6 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.8 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | change_and_configuration_management_database | 7.2 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | tivoli_service_request_manager | 7.1.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5 |
| ibm | tivoli_asset_management_for_it | 7.1 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | spectrum_scale | 4.2.0.0 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | spectrum_scale | 4.1.1.1 |
IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_statistics | 22.0.0.2 |
| ibm | spss_statistics | 23.0.0.2 |
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 8.5.0.2 |
| ibm | infosphere_information_server | 9.1.0.1 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 8.5.0.1 |
| ibm | infosphere_information_server | 9.1.2 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 11.3.1 |
| ibm | infosphere_information_server | 8.7.0.2 |
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 8.5.0.3 |
| ibm | infosphere_information_server | 8.7.0.1 |
| ibm | infosphere_information_server | 8.7 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_reference_data_management | 10.1 |
| ibm | infosphere_master_data_management_reference_data_management | 11.3 |
| ibm | infosphere_master_data_management_reference_data_management | 11.5 |
| ibm | infosphere_master_data_management_reference_data_management | 11.4 |
| ibm | infosphere_master_data_management_reference_data_management | 11.0 |
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 8.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.3 |
| ibm | smartcloud_orchestrator | 2.3 |
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | smartcloud_orchestrator | 2.3.0.1 |
| ibm | cloud_orchestrator | 2.4.0.2 |
| ibm | cloud_orchestrator | 2.4 |
| ibm | cloud_orchestrator | 2.5 |
| ibm | cloud_orchestrator | 2.5.01 |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_networking_switch_center | * |
| lenovo | switch_center | * |
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_networking_switch_center | * |
| lenovo | switch_center | * |
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_networking_switch_center | * |
| lenovo | switch_center | * |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_networking_switch_center | * |
| lenovo | switch_center | * |
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CVE-2015-8521, and CVE-2015-8522.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.12.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.12 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8521, and CVE-2015-8522.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.12.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.12 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8522.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.12.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.12 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8521.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.12.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.12 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.12.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.12 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 8.5.0.2 |
Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long argument.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_statistics | * |
| ibm | spss_statistics | 24.0.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_network_protection_firmware | 5.3.1 |
| ibm | security_network_protection_firmware | 5.3.2 |
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.3 |
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | cloud_orchestrator | 2.3.0.1 |
| ibm | cloud_orchestrator | 2.3 |
| ibm | cloud_orchestrator | 2.4.0.2 |
| ibm | cloud_orchestrator | 2.4 |
A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.3 |
| ibm | smartcloud_orchestrator | 2.3 |
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | smartcloud_orchestrator | 2.3.0.1 |
| ibm | cloud_orchestrator | 2.4.0.2 |
| ibm | cloud_orchestrator | 2.4 |
| ibm | cloud_orchestrator | 2.5 |
| ibm | cloud_orchestrator | 2.5.01 |
Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | cloud_orchestrator | 2.4.0.0 |
| ibm | cloud_orchestrator | 2.4.0.2 |
A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | cloud_orchestrator | 2.3.0.1 |
| ibm | cloud_orchestrator | 2.3.0.0 |
| ibm | cloud_orchestrator | 2.4.0.0 |
IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_orchestrator | 2.4.0.1 |
| ibm | cloud_orchestrator | 2.3.0.1 |
| ibm | cloud_orchestrator | 2.3 |
| ibm | cloud_orchestrator | 2.4.0.2 |
| ibm | cloud_orchestrator | 2.4 |
IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_risk_application | * |
IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.1 |
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 9.8.0.1 |
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 9.8.0.3 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 9.8 |
| ibm | db2_connect | 9.8 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 9.8.0.5 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2 | 9.8.0.4 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2_connect | 9.8.0.4 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.8.0.2 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.8.0.1 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 9.8.0.3 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 9.8.0.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
| ibm | db2_connect | 9.8.0.2 |
Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0216.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.0.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.8 |
| ibm | db2 | 9.7 |
Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0213.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | 6.1.0.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.8.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.9 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.2.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.10 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5 |
| ibm | tivoli_storage_manager_fastback | 6.1.11 |
| ibm | tivoli_storage_manager_fastback | 6.1.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.5.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.9.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.0 |
| ibm | tivoli_storage_manager_fastback | 5.5.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.8 |
| ibm | tivoli_storage_manager_fastback | 6.1.6.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.2 |
| ibm | tivoli_storage_manager_fastback | 6.1.6 |
| ibm | tivoli_storage_manager_fastback | 6.1.11.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.4 |
| ibm | tivoli_storage_manager_fastback | 6.1.7 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.3.0 |
| ibm | tivoli_storage_manager_fastback | 6.1.7.1 |
| ibm | tivoli_storage_manager_fastback | 6.1.1.0 |
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 3.0.1.2 |
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.4 |
| ibm | rational_requirements_composer | 3.0.1.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_team_concert | 3.0.1.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_team_concert | 3.0.1.1 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_requirements_composer | 3.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 3.0.1.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.4 |
| ibm | rational_quality_manager | 3.0.1.3 |
| ibm | rational_team_concert | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 3.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 3.0.1.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 3.0.1.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_requirements_composer | 3.0.1.6 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.5 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 3.0.1.2 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_requirements_composer | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.3 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 3.0.1.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_team_concert | 3.0 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1 |
| ibm | rational_requirements_composer | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.5 |
| ibm | rational_team_concert | 3.0.1.3 |
| ibm | rational_quality_manager | 3.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_team_concert | 5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_life_sciences | - |
| ibm | smartcloud_control_desk | - |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_for_transportation | - |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_for_oil_and_gas | - |
| ibm | maximo_for_government | - |
| ibm | maximo_for_nuclear_power | - |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_for_utilities | - |
| ibm | maximo_asset_management | 7.6.0.2 |
Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_server | 8.0.0.0 |
| ibm | forms_server | 4.0.0.0 |
| ibm | forms_server | 8.1.0.0 |
| ibm | forms_server | 8.0.1.0 |
| ibm | forms_server | 8.2.0.0 |
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 8.6.0.1 |
| ibm | marketing_platform | 8.5.0.5 |
| ibm | marketing_platform | 8.6.0.6 |
| ibm | marketing_platform | 9.1.0.3 |
| ibm | marketing_platform | 9.1.0.6 |
| ibm | marketing_platform | 8.5.0.6 |
| ibm | marketing_platform | 9.1.0.7 |
| ibm | marketing_platform | 8.6.0.3 |
| ibm | marketing_platform | 8.6.0.9 |
| ibm | marketing_platform | 9.1.0.4 |
| ibm | marketing_platform | 9.1.1.1 |
| ibm | marketing_platform | 9.0.0.4 |
| ibm | marketing_platform | 9.1.1.0 |
| ibm | marketing_platform | 8.5.0.7 |
| ibm | marketing_platform | 9.1.1.2 |
| ibm | marketing_platform | 8.6.0.5 |
| ibm | marketing_platform | 9.0.0.1 |
| ibm | marketing_platform | 8.6.0.0 |
| ibm | marketing_platform | 8.6.0.10 |
| ibm | marketing_platform | 9.0.0.2 |
| ibm | marketing_platform | 9.1.1.4 |
| ibm | marketing_platform | 8.5.0.2 |
| ibm | marketing_platform | 9.1.0.8 |
| ibm | marketing_platform | 8.5.0.3 |
| ibm | marketing_platform | 9.1.0.9 |
| ibm | marketing_platform | 8.5.0.1 |
| ibm | marketing_platform | 8.6.0.11 |
| ibm | marketing_platform | 9.1.0.2 |
| ibm | marketing_platform | 8.6.0.7 |
| ibm | marketing_platform | 8.6.0.2 |
| ibm | marketing_platform | 8.6.0.8 |
| ibm | marketing_platform | 9.1.0.5 |
| ibm | marketing_platform | 8.6.0.4 |
| ibm | marketing_platform | 8.5.0.4 |
| ibm | marketing_platform | 9.1.1.3 |
| ibm | marketing_platform | 9.0.0.0 |
| ibm | marketing_platform | 9.0.0.3 |
| ibm | marketing_platform | 8.5.0.0 |
| ibm | marketing_platform | 9.1.2.0 |
| ibm | marketing_platform | 9.1.0.0 |
| ibm | marketing_platform | 9.1.0.10 |
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 11.70.xcn |
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 8.5.0.2 |
IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM X-Force ID: 110236.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 10.0 |
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 8.6.0.1 |
| ibm | marketing_platform | 8.6.0.6 |
| ibm | marketing_platform | 9.1.0.3 |
| ibm | marketing_platform | 9.1.0.6 |
| ibm | marketing_platform | 9.1.0.7 |
| ibm | marketing_platform | 8.6.0.3 |
| ibm | marketing_platform | 8.6.0.9 |
| ibm | marketing_platform | 9.1.0.4 |
| ibm | marketing_platform | 9.1.1.1 |
| ibm | marketing_platform | 9.0.0.4 |
| ibm | marketing_platform | 9.1.1.0 |
| ibm | marketing_platform | 9.1.1.2 |
| ibm | marketing_platform | 8.6.0.5 |
| ibm | marketing_platform | 9.0.0.1 |
| ibm | marketing_platform | 8.6.0.0 |
| ibm | marketing_platform | 8.6.0.10 |
| ibm | marketing_platform | 9.0.0.2 |
| ibm | marketing_platform | 9.1.1.4 |
| ibm | marketing_platform | 9.1.0.8 |
| ibm | marketing_platform | 9.1.0.9 |
| ibm | marketing_platform | 8.6.0.11 |
| ibm | marketing_platform | 9.1.0.2 |
| ibm | marketing_platform | 8.6.0.7 |
| ibm | marketing_platform | 8.6.0.2 |
| ibm | marketing_platform | 8.6.0.8 |
| ibm | marketing_platform | 9.1.0.5 |
| ibm | marketing_platform | 8.6.0.4 |
| ibm | marketing_platform | 9.1.1.3 |
| ibm | marketing_platform | 9.0.0.0 |
| ibm | marketing_platform | 9.0.0.3 |
| ibm | marketing_platform | 9.1.2.0 |
| ibm | marketing_platform | 9.1.0.0 |
| ibm | marketing_platform | 9.1.0.10 |
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.8 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | hardware_management_console | 8.3.0 |
| ibm | hardware_management_console | 7.9.0 |
| ibm | hardware_management_console | 8.1.0 |
| ibm | hardware_management_console | 8.4.0 |
| ibm | hardware_management_console | 8.5.0 |
| ibm | hardware_management_console | 8.2.0 |
| ibm | hardware_management_console | 7.3.0 |
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.0 |
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.4 |
| ibm | financial_transaction_manager | 3.0.0.9 |
| ibm | financial_transaction_manager | 3.0.0.7 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 3.0.0.11 |
| ibm | financial_transaction_manager | 3.0.0.3 |
| ibm | financial_transaction_manager | 3.0.0.10 |
| ibm | financial_transaction_manager | 3.0.0.2 |
| ibm | financial_transaction_manager | 3.0.0.5 |
| ibm | financial_transaction_manager | 3.0.0.8 |
| ibm | financial_transaction_manager | 3.0.0.6 |
| ibm | financial_transaction_manager | 3.0.0.1 |
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 9.1.0.1 |
| ibm | marketing_platform | 8.6.0.1 |
| ibm | marketing_platform | 8.5.0.5 |
| ibm | marketing_platform | 8.6.0.6 |
| ibm | marketing_platform | 9.1.0.3 |
| ibm | marketing_platform | 9.1.0.6 |
| ibm | marketing_platform | 8.5.0.6 |
| ibm | marketing_platform | 9.1.0.7 |
| ibm | marketing_platform | 8.6.0.3 |
| ibm | marketing_platform | 8.6.0.9 |
| ibm | marketing_platform | 9.1.0.4 |
| ibm | marketing_platform | 9.1.1.1 |
| ibm | marketing_platform | 9.0.0.4 |
| ibm | marketing_platform | 9.1.1.0 |
| ibm | marketing_platform | 8.5.0.7 |
| ibm | marketing_platform | 9.1.1.2 |
| ibm | marketing_platform | 8.6.0.5 |
| ibm | marketing_platform | 9.0.0.1 |
| ibm | marketing_platform | 8.6.0.0 |
| ibm | marketing_platform | 8.6.0.10 |
| ibm | marketing_platform | 9.0.0.2 |
| ibm | marketing_platform | 9.1.1.4 |
| ibm | marketing_platform | 8.5.0.2 |
| ibm | marketing_platform | 9.1.0.8 |
| ibm | marketing_platform | 8.5.0.3 |
| ibm | marketing_platform | 9.1.0.9 |
| ibm | marketing_platform | 8.5.0.1 |
| ibm | marketing_platform | 8.6.0.11 |
| ibm | marketing_platform | 9.1.0.2 |
| ibm | marketing_platform | 8.6.0.7 |
| ibm | marketing_platform | 8.6.0.2 |
| ibm | marketing_platform | 8.6.0.8 |
| ibm | marketing_platform | 9.1.0.5 |
| ibm | marketing_platform | 8.6.0.4 |
| ibm | marketing_platform | 8.5.0.4 |
| ibm | marketing_platform | 9.1.1.3 |
| ibm | marketing_platform | 9.0.0.0 |
| ibm | marketing_platform | 9.0.0.3 |
| ibm | marketing_platform | 8.5.0.0 |
| ibm | marketing_platform | 9.1.2.0 |
| ibm | marketing_platform | 9.1.0.0 |
| ibm | marketing_platform | 9.1.0.10 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.
CVSS 2.0
Severity: LOW
Problem Type: CWE-613,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | * |
| ibm | openpages_grc_platform | 7.3.0.0 |
IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 10.0 |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 8.2 |
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 10.01 |
| ibm | security_guardium_database_activity_monitor | 10.1 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 10.0 |
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 9.5 |
IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 10.0.1 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 8.2 |
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 10.01 |
| ibm | security_guardium_database_activity_monitor | 10.1 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 8.2 |
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 10.01 |
| ibm | security_guardium_database_activity_monitor | 10.1 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.01 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.01 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 8.2 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 9.5 |
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.01 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 8.2 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 9.5 |
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0 |
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 9.5 |
| ibm | security_guardium | * |
| ibm | security_guardium | 10.1.0 |
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | * |
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_control_center | 5.4.0.1 |
| ibm | sterling_control_center | 5.4.1 |
| ibm | sterling_control_center | 5.4.1.0 |
| ibm | control_center | 6.0.0.0 |
| ibm | sterling_control_center | 5.4.2 |
| ibm | sterling_control_center | 5.4.2.0 |
| ibm | sterling_control_center | 5.4.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
| ibm | financial_transaction_manager | 2.1.1.2 |
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 110564.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 10.0 |
| ibm | marketing_platform | 9.1 |
| ibm | marketing_platform | 9.1.2 |
| ibm | marketing_platform | 9.1.1 |
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0.0.2 |
Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | care_management | 6.0 |
| ibm | curam_social_program_management | * |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.1 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.3 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_asset_management | 7.6.0.2 |
IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system_storage_server | 3.5.0.3 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.2 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.27 |
| ibm | spectrum_scale | 4.2.0.0 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.9 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.15 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.17 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.24 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.28 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.7 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.11 |
| ibm | spectrum_scale | 4.1.1.3 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.8 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.29 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.26 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.1 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.4 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.14 |
| ibm | spectrum_scale | 4.1.1.4 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.10 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.5 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.12 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.16 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.6 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.21 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.22 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.19 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.13 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.25 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.20 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.23 |
| ibm | general_parallel_file_system_storage_server | 3.5.0.18 |
| ibm | spectrum_scale | 4.2.0.1 |
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.6 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L | 2.2 | 3.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | satellite | 5.6 |
| suse | linux_enterprise_software_development_kit | 11 |
| redhat | enterprise_linux_workstation | 7.0 |
| suse | linux_enterprise_software_development_kit | 12 |
| suse | manager_proxy | 2.1 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_hpc_node_supplementary | 7.0 |
| suse | manager | 2.1 |
| suse | openstack_cloud | 5 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_hpc_node_supplementary | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| suse | suse_linux_enterprise_server | 12 |
| suse | linux_enterprise_server | 11 |
| redhat | enterprise_linux_desktop | 7.0 |
| suse | linux_enterprise_server | 10 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_server_eus | 7.4 |
| ibm | java_sdk | * |
| suse | linux_enterprise_server | 12 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server | 5.0 |
IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | 8.6 |
| ibm | campaign | 9.1 |
| ibm | campaign | 9.1.1 |
| ibm | campaign | 9.1.2 |
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | vios | 2.2.3.70 |
| ibm | vios | 2.2.2.2 |
| ibm | vios | 2.2.2.5 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.4.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | vios | 2.2.4.22 |
| ibm | vios | 2.2.3.52 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.3.50 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.3.51 |
| ibm | vios | 2.2.3.60 |
| ibm | vios | 2.2.4.10 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.4.21 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
| ibm | financial_transaction_manager | 2.1.1.2 |
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2.2 |
| ibm | bigfix_platform | 9.0.5 |
| ibm | bigfix_platform | 9.2.0 |
| ibm | bigfix_platform | 9.1.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.2.1 |
| ibm | bigfix_platform | 9.0.8 |
| ibm | bigfix_platform | 9.1.3 |
| ibm | bigfix_platform | 9.1.6 |
| ibm | bigfix_platform | 9.2.4 |
| ibm | bigfix_platform | 9.2.5 |
| ibm | bigfix_platform | 9.0.7 |
| ibm | bigfix_platform | 9.1.4 |
| ibm | bigfix_platform | 9.1.5 |
| ibm | bigfix_platform | 9.0.6 |
| ibm | bigfix_platform | 9.2.3 |
IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 9.0.1.4 |
| ibm | client_application_access | 1.0.0.1 |
| ibm | notes | 9.0.1.5 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1.5 |
| ibm | notes | 9.0.1.3 |
| ibm | notes | 9.0.1.4 |
The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
| ibm | financial_transaction_manager | 2.1.1.2 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM X-Force ID: 111076.
CVSS 2.0
Severity: LOW
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
| ibm | financial_transaction_manager | 2.1.1.2 |
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
| ibm | financial_transaction_manager | 2.1.1.2 |
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. IBM X-Force ID: 111084.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0278, CVE-2016-0279, and CVE-2016-0301.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.1.3 |
| ibm | domino | 8.5.2.3 |
Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0279, and CVE-2016-0301.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.1.3 |
| ibm | domino | 8.5.2.3 |
Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0301.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.1.3 |
| ibm | domino | 8.5.2.3 |
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | information_server_framework | 11.3 |
| ibm | infosphere_information_governance_catalog | 11.3 |
| ibm | information_server_framework | 11.5 |
| ibm | information_server_framework | 8.7 |
| ibm | infosphere_information_server_business_glossary | 9.1 |
| ibm | infosphere_information_server_business_glossary | 8.7 |
| ibm | infosphere_information_governance_catalog | 11.5 |
| ibm | information_server_framework | 8.5 |
| ibm | information_server_framework | 9.1 |
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | vios | 2.2.2.2 |
| ibm | vios | 2.2.2.5 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_inotes | 8.5.1.3 |
| ibm | lotus_inotes | 8.5.1.0 |
| ibm | lotus_inotes | 8.5.3.0 |
| ibm | lotus_inotes | 8.5.2.2 |
| ibm | lotus_inotes | 8.5.0.0 |
| ibm | lotus_inotes | 8.5.1.5 |
| ibm | lotus_inotes | 8.5.2.3 |
| ibm | lotus_inotes | 8.5.2.1 |
| ibm | lotus_inotes | 8.5.1.1 |
| ibm | lotus_inotes | 8.5.2.0 |
| ibm | lotus_inotes | 8.5.3.1 |
| ibm | lotus_inotes | 8.5.1.4 |
| ibm | lotus_inotes | 8.5.3.3 |
| ibm | lotus_inotes | 8.5.1.2 |
| ibm | lotus_inotes | 8.5.3.6 |
| ibm | lotus_inotes | 8.5.2.4 |
| ibm | lotus_inotes | 8.5.3.4 |
| ibm | lotus_inotes | 8.5.3.5 |
| ibm | lotus_inotes | 8.5.0.1 |
| ibm | lotus_inotes | 8.5.3.2 |
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.5.5.1 |
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted field.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_team_concert | 6.0.2 |
IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obtain administrator passwords by leveraging unspecified privileges. BM X-Force ID: 111234.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_service_manager | 6.1.0 |
| ibm | tivoli_business_service_manager | 6.1.1 |
IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | 7.1 |
IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 8.8.0.0 |
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.1.1 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 9.0.3.0 |
| ibm | security_appscan | 9.0.3.1 |
| ibm | security_appscan | 9.0.2.0 |
| ibm | security_appscan | 8.7.0.0 |
| ibm | security_appscan | 8.7.0.1 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 9.0.2.1 |
shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_asset_management | 7.6.0.2 |
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
| ibm | bigfix_platform | 9.0 |
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix | 9.5 |
| ibm | bigfix | 9.1 |
| ibm | bigfix | 9.0 |
| ibm | bigfix | 9.2 |
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2.2 |
| ibm | bigfix_platform | 9.0.5 |
| ibm | bigfix_platform | 9.2.0 |
| ibm | bigfix_platform | 9.1.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.2.1 |
| ibm | bigfix_platform | 9.0.8 |
| ibm | bigfix_platform | 9.1.3 |
| ibm | bigfix_platform | 9.1.6 |
| ibm | bigfix_platform | 9.2.4 |
| ibm | bigfix_platform | 9.2.5 |
| ibm | bigfix_platform | 9.0.7 |
| ibm | bigfix_platform | 9.1.4 |
| ibm | bigfix_platform | 9.1.5 |
| ibm | bigfix_platform | 9.0.6 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.3 |
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | * |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.0 |
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | * |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0279.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.1.3 |
| ibm | domino | 8.5.2.3 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_integrated_portal | * |
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.0 |
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 8.5.1 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.2.3 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.2 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 8.5.2.4 |
| ibm | domino | 8.5.1.3 |
IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_business_service_manager | 6.1.0 |
| ibm | tivoli_business_service_manager | 6.1.1 |
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | * |
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | personal_communications | 6.0.7 |
| ibm | personal_communications | 6.0.5 |
| ibm | personal_communications | 6.0.8 |
| ibm | personal_communications | 6.0.10 |
| ibm | personal_communications | 6.0.13 |
| ibm | personal_communications | 12.0.0 |
| ibm | personal_communications | 6.0.11 |
| ibm | personal_communications | 6.0.0 |
| ibm | personal_communications | 6.0.1 |
| ibm | personal_communications | 6.0.9 |
| ibm | personal_communications | 6.0.16 |
| ibm | personal_communications | 6.0.15 |
| ibm | personal_communications | 6.0.12 |
| ibm | personal_communications | 6.0.2 |
| ibm | personal_communications | 6.0.4 |
| ibm | personal_communications | 6.0.3 |
| ibm | personal_communications | 6.0.6 |
| ibm | personal_communications | 6.0.14 |
Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bluemix | - |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to execute arbitrary OS commands via a crafted request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_team_concert | 6.0.2 |
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 8.2 |
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 10.01 |
| ibm | security_guardium_database_activity_monitor | 10.1 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 111692.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | * |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_adapter | 7.0.0.2 |
| ibm | security_identity_manager_adapter | 7.0.0.3 |
| ibm | security_identity_manager_adapter | 7.0.1.0 |
| ibm | security_identity_manager_adapter | 7.0.0.1 |
| ibm | security_identity_manager_adapter | 7.0.0.0 |
| ibm | security_identity_manager_adapter | 7.0.1.1 |
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_team_concert | 6.0.2 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0.1.0 |
| ibm | security_identity_manager | 7.0.0.1 |
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_identity_manager | 7.0.0.3 |
| ibm | security_identity_manager | 7.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0.1.0 |
| ibm | security_identity_manager | 7.0.0.1 |
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_identity_manager | 7.0.0.3 |
| ibm | security_identity_manager | 7.0.0.2 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_adapter | 7.0.0.2 |
| ibm | security_identity_manager_adapter | 7.0.0.3 |
| ibm | security_identity_manager_adapter | 7.0.1.0 |
| ibm | security_identity_manager_adapter | 7.0.0.1 |
| ibm | security_identity_manager_adapter | 7.0.0.0 |
| ibm | security_identity_manager_adapter | 7.0.1.1 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_adapter | 7.0.0.2 |
| ibm | security_identity_manager_adapter | 7.0.0.3 |
| ibm | security_identity_manager_adapter | 7.0.1.0 |
| ibm | security_identity_manager_adapter | 7.0.0.1 |
| ibm | security_identity_manager_adapter | 7.0.0.0 |
| ibm | security_identity_manager_adapter | 7.0.1.1 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_adapter | 7.0.0.2 |
| ibm | security_identity_manager_adapter | 7.0.0.3 |
| ibm | security_identity_manager_adapter | 7.0.1.0 |
| ibm | security_identity_manager_adapter | 7.0.0.1 |
| ibm | security_identity_manager_adapter | 7.0.0.0 |
| ibm | security_identity_manager_adapter | 7.0.1.1 |
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | b2b_advanced_communications | 1.0.0.2 |
| ibm | b2b_advanced_communications | 1.0.0.1 |
| ibm | b2b_advanced_communications | 1.0 |
| ibm | b2b_advanced_communications | 1.0.0.3 |
| ibm | multi-enterprise_integration_gateway | 1.0.0 |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | * |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | * |
Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | * |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | * |
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.7.0 |
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.1.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.0.1 |
| ibm | security_privileged_identity_manager | 2.0.0 |
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_adapter | 7.0.0.2 |
| ibm | security_identity_manager_adapter | 7.0.0.3 |
| ibm | security_identity_manager_adapter | 7.0.1.0 |
| ibm | security_identity_manager_adapter | 7.0.0.1 |
| ibm | security_identity_manager_adapter | 7.0.0.0 |
| ibm | security_identity_manager_adapter | 7.0.1.1 |
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_jms | 8.0 |
| ibm | websphere_mq_jms | 7.1 |
| ibm | websphere_mq_jms | 7.0.1 |
| ibm | websphere_mq_jms | 7.5 |
| ibm | websphere_mq_jms | 9.0 |
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | general_parallel_file_system | 3.5 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 4.1.0.1 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | general_parallel_file_system | 3.5.0.7 |
| ibm | general_parallel_file_system | 3.5.0.16 |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| novell | suse_openstack_cloud | 5 |
| redhat | satellite | 5.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_hpc_node_supplementary | 7.0 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_workstation | 6.0 |
| novell | suse_linux_enterprise_software_development_kit | 11.0 |
| redhat | enterprise_linux_hpc_node_supplementary | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| novell | suse_linux_enterprise_software_development_kit | 12.0 |
| novell | suse_manager | 2.1 |
| novell | suse_linux_enterprise_module_for_legacy_software | 12 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| novell | suse_linux_enterprise_server | 12.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_server_eus | 7.4 |
| ibm | java_sdk | * |
| novell | suse_linux_enterprise_server | 11.0 |
| redhat | enterprise_linux_server_eus | 7.2 |
| novell | suse_manager_proxy | 2.1 |
| redhat | enterprise_linux_server_eus | 7.5 |
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0 |
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.1.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_experience_builder | 8.5.1 |
| ibm | forms_experience_builder | 8.6.0 |
| ibm | forms_experience_builder | 8.5 |
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_experience_builder | 8.5.0.0 |
| ibm | forms_experience_builder | 8.6.0.0 |
| ibm | forms_experience_builder | 8.6.1.1 |
| ibm | forms_experience_builder | 8.6.2 |
| ibm | forms_experience_builder | 8.6.2.1 |
| ibm | forms_experience_builder | 8.5.1.0 |
| ibm | forms_experience_builder | 8.5.1.1 |
| ibm | forms_experience_builder | 8.6.1 |
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-285,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | * |
The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users to gain privileges for application modification via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | messagesight | 1.1.0.0 |
| ibm | messagesight | 1.2 |
| ibm | messagesight | 2.0.0.0 |
| ibm | messagesight | 1.1.0.1 |
| ibm | messagesight | 1.2.0.2 |
| ibm | messagesight | 1.2.0.0 |
| ibm | messagesight | 1.2.0.1 |
| ibm | messagesight | 1.2.0.3 |
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| novell | suse_openstack_cloud | 5 |
| redhat | satellite | 5.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_hpc_node_supplementary | 7.0 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_workstation | 6.0 |
| novell | suse_linux_enterprise_software_development_kit | 11.0 |
| redhat | enterprise_linux_hpc_node_supplementary | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| novell | suse_linux_enterprise_software_development_kit | 12.0 |
| novell | suse_manager | 2.1 |
| novell | suse_linux_enterprise_module_for_legacy_software | 12 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| novell | suse_linux_enterprise_server | 12.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_server_eus | 7.4 |
| ibm | java_sdk | * |
| novell | suse_linux_enterprise_server | 11.0 |
| redhat | enterprise_linux_server_eus | 7.2 |
| novell | suse_manager_proxy | 2.1 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_server_eus | 7.5 |
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.42 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.40 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.
CVSS 2.0
Severity: LOW
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.5.0.5 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 7.5.0.6 |
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N | 1.8 | 1.4 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect:direct | 4.1.0.4 |
| ibm | sterling_connect:direct | 4.1.0.1 |
| ibm | sterling_connect:direct | 4.2.0.3 |
| ibm | sterling_connect:direct | 4.2.0.0 |
| ibm | sterling_connect:direct | 4.1.0.0 |
| ibm | sterling_connect:direct | 4.2.0.4 |
| ibm | sterling_connect:direct | 4.2.0.2 |
| ibm | sterling_connect:direct | 4.2.0.1 |
| ibm | sterling_connect:direct | 4.1.0.2 |
| ibm | sterling_connect:direct | 4.1.0.3 |
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | * |
The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_consumer_experience | 8.7.0 |
| ibm | tealeaf_consumer_experience | 8.8.0 |
| ibm | tealeaf_consumer_experience | 8.8.1 |
| ibm | tealeaf_consumer_experience | 9.0.1 |
| ibm | tealeaf_consumer_experience | 8.7.1 |
| ibm | tealeaf_consumer_experience | 9.0.2 |
| ibm | tealeaf_consumer_experience | 8.8 |
| ibm | tealeaf_consumer_experience | 8.8.2 |
| ibm | tealeaf_consumer_experience | 8.7 |
| ibm | tealeaf_consumer_experience | 9.0 |
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to hijack the authentication of administrators for requests that delete employees.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 5.1.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | watson_developer_cloud | - |
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | elastic_storage_server | 3.5.1 |
| ibm | general_parallel_file_system_storage_server | 2.0.5 |
| ibm | elastic_storage_server | 2.5.3 |
| ibm | elastic_storage_server | 3.0.1 |
| ibm | general_parallel_file_system_storage_server | 2.0.4 |
| ibm | elastic_storage_server | 3.5.4 |
| ibm | elastic_storage_server | 3.5.2 |
| ibm | elastic_storage_server | 3.0.2 |
| ibm | elastic_storage_server | 3.0.3 |
| ibm | elastic_storage_server | 3.5.3 |
| ibm | general_parallel_file_system_storage_server | 2.0.1 |
| ibm | general_parallel_file_system_storage_server | 2.0.2 |
| ibm | elastic_storage_server | 4.0.0 |
| ibm | elastic_storage_server | 2.5.2 |
| ibm | elastic_storage_server | 4.0.1 |
| ibm | elastic_storage_server | 2.5.1 |
| ibm | general_parallel_file_system_storage_server | 2.0.3 |
| ibm | elastic_storage_server | 3.0.5 |
| ibm | elastic_storage_server | 4.0.2 |
| ibm | elastic_storage_server | 2.5.5 |
| ibm | elastic_storage_server | 2.5.0 |
| ibm | general_parallel_file_system_storage_server | 2.0.7 |
| ibm | elastic_storage_server | 3.5.0 |
| ibm | general_parallel_file_system_storage_server | 2.0.0 |
| ibm | elastic_storage_server | 2.5.4 |
| ibm | elastic_storage_server | 3.0.4 |
| ibm | general_parallel_file_system_storage_server | 2.0.6 |
| ibm | elastic_storage_server | 3.0.0 |
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.6.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_asset_management | 7.6.0.2 |
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
CVSS 2.0
Severity: LOW
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 10.0 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.4 |
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_webreports | 9.0 |
| ibm | bigfix_webreports | 9.1 |
| ibm | bigfix_webreports | 9.5 |
| ibm | bigfix_webreports | 9.2 |
IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.3 |
| ibm | maximo_asset_management | 7.6.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0.4 |
| ibm | websphere_extreme_scale | 8.6.0.6 |
| ibm | websphere_extreme_scale | 8.6.0.2 |
| ibm | websphere_extreme_scale | 8.5.0.2 |
| ibm | websphere_extreme_scale | 8.6.0.1 |
| ibm | websphere_extreme_scale | 8.6.0.5 |
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 8.6.0.7 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 8.5.0 |
| ibm | websphere_extreme_scale | 8.6.0.3 |
| ibm | websphere_extreme_scale | 8.6.0.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
| ibm | websphere_extreme_scale | 8.5.0.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| opensuse | leap | 42.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_container_platform | 3.2 |
| redhat | openshift_container_platform | 3.1 |
| ibm | api_connect | * |
| salesforce | tough-cookie | * |
| redhat | openshift_container_platform | 3.3 |
| ibm | api_connect | 5.0.8.0 |
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-311,CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ibm_db | * |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_extreme_scale | 8.6.0 |
| ibm | websphere_extreme_scale | 8.6.0.4 |
| ibm | websphere_extreme_scale | 8.6.0.6 |
| ibm | websphere_extreme_scale | 8.6.0.2 |
| ibm | websphere_extreme_scale | 8.5.0.2 |
| ibm | websphere_extreme_scale | 8.6.0.1 |
| ibm | websphere_extreme_scale | 8.6.0.5 |
| ibm | websphere_extreme_scale | 7.1.0.2 |
| ibm | websphere_extreme_scale | 8.6.0.7 |
| ibm | websphere_extreme_scale | 7.1.0 |
| ibm | websphere_extreme_scale | 8.5.0 |
| ibm | websphere_extreme_scale | 8.6.0.3 |
| ibm | websphere_extreme_scale | 8.6.0.0 |
| ibm | websphere_extreme_scale | 7.1.1 |
| ibm | websphere_extreme_scale | 8.5.0.1 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 7.0.0.8 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.0.2 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_team_concert | 5.0.1 |
An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_streams | * |
| ibm | streams | * |
IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | * |
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
Buffer overflow in the CLI on IBM WebSphere DataPower XC10 appliances 2.1 and 2.5 allows remote authenticated users to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | 2.1 |
| ibm | websphere_datapower_xc10_appliance_firmware | 2.5 |
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.6 |
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341.
CVSS 2.0
Severity: LOW
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.
CVSS 2.0
Severity: LOW
Problem Type: CWE-320,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0387.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_experience_builder | 8.5.0.0 |
| ibm | forms_experience_builder | 8.6.0.0 |
| ibm | forms_experience_builder | 8.6.1.1 |
| ibm | forms_experience_builder | 8.6.2 |
| ibm | forms_experience_builder | 8.6.2.1 |
| ibm | forms_experience_builder | 8.5.1.0 |
| ibm | forms_experience_builder | 8.6.3 |
| ibm | forms_experience_builder | 8.5.1.1 |
| ibm | forms_experience_builder | 8.6.1 |
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | ims_enterprise_suite | * |
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016, 6.0 and 6.0.1 before 6.0.1 ifix005, and 6.0.2 before ifix002 allows remote authenticated users to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 5.5.4.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.4.1.7 |
| ibm | tivoli_storage_manager | 5.5.4 |
| ibm | tivoli_storage_manager | 6.2.4.7 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 5.5 |
| ibm | tivoli_storage_manager | 7.1.2 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 6.3.0 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 5.5.4.3 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.0.4 |
| ibm | tivoli_storage_manager | 6.4 |
| ibm | tivoli_storage_manager | 6.4.0 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.0.7 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 6.4.0.5 |
| ibm | tivoli_storage_manager | 6.4.0.1 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 5.5.4.2 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.4.1.3 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 5.5.3 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 6.2 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_content_manager | * |
| ibm | websphere_portal | 8.5.0.0 |
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 2.0.1 |
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 2.0.1 |
The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 10.4 |
| ibm | tririga_application_platform | 10.5 |
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearquest | * |
IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.5.5.1 |
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | biginsights | 4.2 |
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID: 5512.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | 9.1.3 |
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-91,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 8.5.5.9 |
Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 3.0.1.6 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 3.0.1.6 |
| ibm | rational_quality_manager | 3.0.1.6 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | 9.1.2 |
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-3008.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 10.0.0.3 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.6 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | integration_bus | 9.0 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 10.0 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | integration_bus | 10.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.7 |
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | * |
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.1.1 |
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 8.5.1.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime away message altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113848.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_incident_forensics | 7.2.0 |
| ibm | security_qradar_incident_forensics | 7.2.2 |
| ibm | security_qradar_incident_forensics | 7.2.1 |
| ibm | security_qradar_incident_forensics | 7.2.5 |
| ibm | security_qradar_incident_forensics | 7.2.3 |
| ibm | security_qradar_incident_forensics | 7.2.4 |
| ibm | security_qradar_incident_forensics | 7.2.6 |
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113935.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sametime | 8.5.2.0 |
| ibm | sametime | 8.5.2.1 |
| ibm | sametime | 9.0.0.1 |
| ibm | sametime | 9.0.0.0 |
| ibm | sametime | 9.0.1 |
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.2.0.2 |
| ibm | general_parallel_file_system | 3.5.0.0 |
| ibm | spectrum_scale | 4.2.0.0 |
| ibm | general_parallel_file_system | 4.1.0.0 |
| ibm | general_parallel_file_system | 4.1.0.1 |
| ibm | general_parallel_file_system | 3.5.0.20 |
| ibm | general_parallel_file_system | 3.5.0.14 |
| ibm | spectrum_scale | 4.1.1.3 |
| ibm | general_parallel_file_system | 3.5.0.10 |
| ibm | general_parallel_file_system | 3.5.0.21 |
| ibm | general_parallel_file_system | 3.5.0.4 |
| ibm | general_parallel_file_system | 3.5.0.16 |
| ibm | spectrum_scale | 4.1.1.8 |
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | spectrum_scale | 4.1.1.4 |
| ibm | spectrum_scale | 4.1.1.5 |
| ibm | general_parallel_file_system | 4.1.0.7 |
| ibm | general_parallel_file_system | 3.5.0.25 |
| ibm | general_parallel_file_system | 3.5.0.6 |
| ibm | general_parallel_file_system | 3.5.0.8 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | general_parallel_file_system | 3.5.0.23 |
| ibm | general_parallel_file_system | 3.5.0.26 |
| ibm | general_parallel_file_system | 3.5.0.27 |
| ibm | general_parallel_file_system | 3.5.0.18 |
| ibm | general_parallel_file_system | 4.1.0.6 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | spectrum_scale | 4.2.0.1 |
| ibm | spectrum_scale | 4.1.1.6 |
| ibm | general_parallel_file_system | 4.1.0.2 |
| ibm | general_parallel_file_system | 4.1.0.8 |
| ibm | general_parallel_file_system | 3.5.0.5 |
| ibm | general_parallel_file_system | 3.5.0.19 |
| ibm | spectrum_scale | 4.1.1.7 |
| ibm | general_parallel_file_system | 3.5.0.30 |
| ibm | general_parallel_file_system | 4.1.0.3 |
| ibm | general_parallel_file_system | 3.5.0.22 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 3.5.0.24 |
| ibm | general_parallel_file_system | 3.5.0.1 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | general_parallel_file_system | 3.5.0.15 |
| ibm | general_parallel_file_system | 4.1.0.4 |
| ibm | general_parallel_file_system | 3.5.0.2 |
| ibm | general_parallel_file_system | 3.5.0.17 |
| ibm | general_parallel_file_system | 3.5.0.12 |
| ibm | general_parallel_file_system | 3.5.0.31 |
| ibm | spectrum_scale | 4.2.0.3 |
| ibm | general_parallel_file_system | 3.5.0.13 |
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | general_parallel_file_system | 3.5.0.29 |
| ibm | general_parallel_file_system | 3.5.0.7 |
| ibm | general_parallel_file_system | 3.5.0.28 |
| ibm | general_parallel_file_system | 4.1.0.5 |
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.2.0.2 |
| ibm | general_parallel_file_system | 3.5.0.0 |
| ibm | spectrum_scale | 4.2.0.0 |
| ibm | general_parallel_file_system | 4.1.0.0 |
| ibm | general_parallel_file_system | 4.1.0.1 |
| ibm | general_parallel_file_system | 3.5.0.20 |
| ibm | general_parallel_file_system | 3.5.0.14 |
| ibm | spectrum_scale | 4.1.1.3 |
| ibm | general_parallel_file_system | 3.5.0.10 |
| ibm | general_parallel_file_system | 3.5.0.21 |
| ibm | general_parallel_file_system | 3.5.0.4 |
| ibm | general_parallel_file_system | 3.5.0.16 |
| ibm | spectrum_scale | 4.1.1.8 |
| ibm | general_parallel_file_system | 3.5.0.3 |
| ibm | spectrum_scale | 4.1.1.4 |
| ibm | spectrum_scale | 4.1.1.5 |
| ibm | general_parallel_file_system | 4.1.0.7 |
| ibm | general_parallel_file_system | 3.5.0.25 |
| ibm | general_parallel_file_system | 3.5.0.6 |
| ibm | general_parallel_file_system | 3.5.0.8 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | general_parallel_file_system | 3.5.0.23 |
| ibm | general_parallel_file_system | 3.5.0.26 |
| ibm | general_parallel_file_system | 3.5.0.27 |
| ibm | general_parallel_file_system | 3.5.0.18 |
| ibm | general_parallel_file_system | 4.1.0.6 |
| ibm | general_parallel_file_system | 3.5.0.11 |
| ibm | spectrum_scale | 4.2.0.1 |
| ibm | spectrum_scale | 4.1.1.6 |
| ibm | general_parallel_file_system | 4.1.0.2 |
| ibm | general_parallel_file_system | 4.1.0.8 |
| ibm | general_parallel_file_system | 3.5.0.5 |
| ibm | general_parallel_file_system | 3.5.0.19 |
| ibm | spectrum_scale | 4.1.1.7 |
| ibm | general_parallel_file_system | 3.5.0.30 |
| ibm | general_parallel_file_system | 4.1.0.3 |
| ibm | general_parallel_file_system | 3.5.0.22 |
| ibm | general_parallel_file_system | 3.5.0.9 |
| ibm | general_parallel_file_system | 3.5.0.24 |
| ibm | general_parallel_file_system | 3.5.0.1 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | general_parallel_file_system | 3.5.0.15 |
| ibm | general_parallel_file_system | 4.1.0.4 |
| ibm | general_parallel_file_system | 3.5.0.2 |
| ibm | general_parallel_file_system | 3.5.0.17 |
| ibm | general_parallel_file_system | 3.5.0.12 |
| ibm | general_parallel_file_system | 3.5.0.31 |
| ibm | spectrum_scale | 4.2.0.3 |
| ibm | general_parallel_file_system | 3.5.0.13 |
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | general_parallel_file_system | 3.5.0.29 |
| ibm | general_parallel_file_system | 3.5.0.7 |
| ibm | general_parallel_file_system | 3.5.0.28 |
| ibm | general_parallel_file_system | 4.1.0.5 |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before 6.0.1 iFix6, and Rational Rhapsody Design Manager 6.x before 6.0.1 iFix6 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_virtual_environments | 6.4 |
| ibm | tivoli_storage_manager_for_virtual_environments | 7.1 |
Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections_portlets | 5.0 |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | lotus_protector_for_mail_security | 2.8 |
| ibm | lotus_protector_for_mail_security | 2.8.1 |
IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | biginsights | 4.2 |
Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.2.0.201 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2997, CVE-2016-3005, and CVE-2016-3010.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.0.1 |
| ibm | security_privileged_identity_manager | 2.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-3005, and CVE-2016-3010.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.
CVSS 2.0
Severity: LOW
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | * |
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3003 and CVE-2016-3006.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3006.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3010.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-3001 and CVE-2016-3003.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2954 and CVE-2016-2956.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 5.5.0.0 |
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.
CVSS 2.0
Severity: LOW
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2995, CVE-2016-2997, and CVE-2016-3005.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 4.5.0.0 |
| ibm | connections | 4.0.0.0 |
| ibm | connections | 5.5.0.0 |
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | network_path_manager | * |
| ibm | api_connect | * |
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.
CVSS 2.0
Severity: LOW
Problem Type: CWE-345,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-358,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.0.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | security_access_manager_for_web | 8.0.1.3 |
| ibm | security_access_manager_for_web | 8.0.0.2 |
| ibm | security_access_manager | 9.0.0.1 |
| ibm | security_access_manager | 9.0.1.0 |
| ibm | security_access_manager_for_web | 8.0.1.0 |
| ibm | security_access_manager_for_web | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.0 |
| ibm | security_access_manager_for_web | 8.0.1.4 |
| ibm | security_access_manager_for_web | 8.0.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | security_access_manager_for_web | 8.0.0.5 |
| ibm | security_access_manager_for_web | 8.0.0.3 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | security_access_manager | 9.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.1.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
| ibm | security_access_manager_for_web | 8.0.1.2 |
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | * |
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | * |
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.13 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.7 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.4 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.11 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.8 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.14 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.10 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.15 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.6 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.16 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.3 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.9 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.12 |
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | security_access_manager_for_mobile | 8.0.0.4 |
| ibm | security_access_manager | 9.0.0.1 |
| ibm | security_access_manager | 9.0.1.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | security_access_manager | 9.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web | 8.0.1 |
| ibm | security_access_manager_for_web | 8.0.1.3 |
| ibm | security_access_manager_for_web | 8.0.0.2 |
| ibm | security_access_manager | 9.0.0.1 |
| ibm | security_access_manager | 9.0.1.0 |
| ibm | security_access_manager_for_web | 8.0.1.4 |
| ibm | security_access_manager_for_web | 8.0.0.4 |
| ibm | security_access_manager_for_web | 7.0.0 |
| ibm | security_access_manager_for_web | 8.0.0.5 |
| ibm | security_access_manager_for_web | 8.0.0 |
| ibm | security_access_manager | 9.0.0 |
| ibm | security_access_manager_for_web | 8.0.1.2 |
IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.3 |
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.0 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.2 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.1.4 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.1.3 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5 |
| ibm | cognos_analytics | 11.0.6 |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | appscan_source | 8.7 |
| ibm | appscan_source | 9.0 |
| ibm | appscan_source | 9.0.3.1 |
| ibm | appscan_source | 9.0.2 |
| ibm | appscan_source | 9.0.3.2 |
| ibm | appscan_source | 8.7.0.1 |
| ibm | appscan_source | 9.0.3 |
| ibm | appscan_source | 8.8 |
| ibm | appscan_source | 9.0.3.3 |
| ibm | appscan_source | 9.0.0.1 |
| ibm | appscan_source | 9.0.1 |
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
CVSS 2.0
Severity: LOW
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 9.0.3 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan_source | 9.0.2 |
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan_source | 9.0.3 |
| ibm | security_appscan_source | 9.0.1 |
| ibm | security_appscan_source | 9.0.2 |
IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 114612.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114614.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | traveler | 8.5.3 |
| ibm | traveler | 9.0 |
| ibm | traveler | 9.0.1 |
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | 2.0 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | * |
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | powerkvm | 2.1.1.3 |
| ibm | powerkvm | 2.1.1.2 |
| ibm | powerkvm | 3.1 |
| ibm | powerkvm | 3.1.0.1 |
| ibm | powerkvm | 2.1.0.2 |
| ibm | powerkvm | 2.1.1.0 |
| ibm | powerkvm | 2.1 |
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.1 |
| ibm | security_access_manager_for_web | 8.0.1.1 |
| ibm | security_access_manager_for_web | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | security_access_manager_for_web | 8.0.1.3 |
| ibm | security_access_manager | 9.0.0.1 |
| ibm | security_access_manager | 9.0.1.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.0 |
| ibm | security_access_manager_for_web | 8.0.1.4 |
| ibm | security_access_manager_for_web | 7.0.0 |
| ibm | security_access_manager_for_web | 8.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | security_access_manager | 9.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
| ibm | security_access_manager_for_web | 8.0.1.2 |
IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace | 4.0.2 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114711.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1 |
| ibm | openpages_grc_platform | 7.3 |
| ibm | openpages_grc_platform | 7.2 |
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | * |
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | * |
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace | 4.0.2 |
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace | 4.0.2 |
Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8.5.7.0 CF2016.09 allows remote authenticated users to inject arbitrary web script or HTML via crafted content.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_databases_data_protection_for_microsoft_sql_server | * |
| ibm | tivoli_storage_flashcopy_manager_for_sql_server | * |
Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.12 |
| ibm | financial_transaction_manager | 3.0.0.4 |
| ibm | financial_transaction_manager | 3.0.0.9 |
| ibm | financial_transaction_manager | 3.0.0.7 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 3.0.0.11 |
| ibm | financial_transaction_manager | 3.0.0.3 |
| ibm | financial_transaction_manager | 3.0.0.10 |
| ibm | financial_transaction_manager | 3.0.1.0 |
| ibm | financial_transaction_manager | 3.0.0.2 |
| ibm | financial_transaction_manager | 3.0.0.5 |
| ibm | financial_transaction_manager | 3.0.0.8 |
| ibm | financial_transaction_manager | 3.0.0.6 |
| ibm | financial_transaction_manager | 3.0.0.1 |
| ibm | financial_transaction_manager | 3.0.0.14 |
| ibm | financial_transaction_manager | 3.0.0.13 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| redhat | enterprise_linux | 7.0 |
| ibm | powerkvm | 3.1 |
| redhat | enterprise_linux | 6.0 |
| oracle | mysql | * |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| ibm | powerkvm | 3.1 |
| canonical | ubuntu_linux | 16.04 |
| oracle | mysql | * |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 15.10 |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: Types.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| ibm | powerkvm | 3.1 |
| canonical | ubuntu_linux | 16.04 |
| oracle | mysql | * |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 15.10 |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| ibm | powerkvm | 3.1 |
| canonical | ubuntu_linux | 16.04 |
| oracle | mysql | * |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 15.10 |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| nodejs | node.js | 5.6.0 |
| nodejs | node.js | 0.12.6 |
| nodejs | node.js | 4.2.1 |
| nodejs | node.js | 5.8.0 |
| nodejs | node.js | 0.10.16-isaacs-manual |
| nodejs | node.js | 4.2.3 |
| nodejs | node.js | 4.1.1 |
| nodejs | node.js | 0.10.13 |
| nodejs | node.js | 4.2.2 |
| nodejs | node.js | 0.10.31 |
| nodejs | node.js | 4.0.0 |
| nodejs | node.js | 5.1.0 |
| ibm | sdk | * |
| nodejs | node.js | 0.10.11 |
| nodejs | node.js | 0.12.0 |
| nodejs | node.js | 5.9.0 |
| nodejs | node.js | 0.10.28 |
| nodejs | node.js | 0.10.39 |
| nodejs | node.js | 5.3.0 |
| nodejs | node.js | 5.8.1 |
| nodejs | node.js | 0.10.41 |
| npmjs | npm | * |
| nodejs | node.js | 0.10.19 |
| nodejs | node.js | 4.3.1 |
| nodejs | node.js | 0.10.10 |
| nodejs | node.js | 0.10.26 |
| nodejs | node.js | 0.12.4 |
| nodejs | node.js | 0.10.6 |
| nodejs | node.js | 0.12.1 |
| nodejs | node.js | 5.2.0 |
| nodejs | node.js | 0.10.3 |
| nodejs | node.js | 0.10.5 |
| nodejs | node.js | 4.4.1 |
| nodejs | node.js | 0.12.2 |
| nodejs | node.js | 5.7.0 |
| nodejs | node.js | 0.10.7 |
| nodejs | node.js | 0.10.33 |
| nodejs | node.js | 0.10.20 |
| nodejs | node.js | 0.10.24 |
| nodejs | node.js | 0.10.35 |
| nodejs | node.js | 0.10.9 |
| nodejs | node.js | 0.10.12 |
| nodejs | node.js | 0.10.29 |
| nodejs | node.js | 0.10.30 |
| nodejs | node.js | 5.4.0 |
| nodejs | node.js | 0.10.16 |
| nodejs | node.js | 0.10.38 |
| nodejs | node.js | 5.7.1 |
| nodejs | node.js | 0.12.7 |
| nodejs | node.js | 4.2.0 |
| nodejs | node.js | 0.10.22 |
| nodejs | node.js | 0.12.5 |
| nodejs | node.js | 0.10.0 |
| nodejs | node.js | 0.10.21 |
| nodejs | node.js | 0.10.37 |
| nodejs | node.js | 0.10.23 |
| nodejs | node.js | 4.2.5 |
| nodejs | node.js | 0.10.14 |
| nodejs | node.js | 4.2.6 |
| nodejs | node.js | 0.12.8 |
| nodejs | node.js | 0.10.34 |
| nodejs | node.js | 5.0.0 |
| nodejs | node.js | 0.10.18 |
| nodejs | node.js | 4.2.4 |
| nodejs | node.js | 0.10.27 |
| nodejs | node.js | 4.3.2 |
| nodejs | node.js | 0.10.15 |
| nodejs | node.js | 0.10.40 |
| nodejs | node.js | 0.12.9 |
| nodejs | node.js | 0.10.8 |
| nodejs | node.js | 4.3.0 |
| nodejs | node.js | 4.1.0 |
| nodejs | node.js | 0.10.36 |
| nodejs | node.js | 4.1.2 |
| nodejs | node.js | 0.10.25 |
| nodejs | node.js | 5.5.0 |
| nodejs | node.js | 0.12.3 |
| nodejs | node.js | 0.10.32 |
| nodejs | node.js | 4.4.0 |
| nodejs | node.js | 5.9.1 |
| nodejs | node.js | 5.4.1 |
| nodejs | node.js | 0.10.2 |
| nodejs | node.js | 0.10.4 |
| nodejs | node.js | 0.10.1 |
| nodejs | node.js | 0.10.17 |
| nodejs | node.js | 5.1.1 |
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 4.6 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 0.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server_tus | 7.6 |
| kernel | util-linux | * |
| redhat | enterprise_linux_eus | 7.7 |
| ibm | powerkvm | 3.1 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_eus | 7.4 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.7 |
| ibm | powerkvm | 2.1 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_eus | 7.5 |
| ibm | power_hardware_management_console | 8.8.6.0 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_eus | 7.3 |
| redhat | enterprise_linux_eus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.6 |
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.2 |
| mariadb | mariadb | * |
| debian | debian_linux | 8.0 |
| ibm | powerkvm | 3.1 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_workstation | 7.0 |
| oracle | mysql | * |
| canonical | ubuntu_linux | 12.04 |
| redhat | enterprise_linux_server_eus | 7.4 |
| canonical | ubuntu_linux | 15.10 |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server_tus | 7.3 |
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_server_aus | 7.2 |
| canonical | ubuntu_linux | 16.04 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_aus | 7.6 |
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.2 |
| mariadb | mariadb | * |
| ibm | powerkvm | 3.1 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_server_aus | 7.3 |
| oracle | mysql | * |
| redhat | enterprise_linux_server_eus | 7.4 |
| oracle | linux | 7 |
| ibm | powerkvm | 2.1 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace | 4.0.2.7 |
| ibm | filenet_workplace | 4.0.2.3 |
| ibm | filenet_workplace | 4.0.2.10 |
| ibm | filenet_workplace | 4.0.2.11 |
| ibm | filenet_workplace | 4.0.2.6 |
| ibm | filenet_workplace | 4.0.2.13 |
| ibm | filenet_workplace | 4.0.2.9 |
| ibm | filenet_workplace | 4.0.2.2 |
| ibm | filenet_workplace | 4.0.2.4 |
| ibm | filenet_workplace | 4.0.2.8 |
| ibm | filenet_workplace | 4.0.2.0 |
| ibm | filenet_workplace | 4.0.2.5 |
| ibm | filenet_workplace | 4.0.2.12 |
| ibm | filenet_workplace | 4.0.2.1 |
MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance_firmware | 8.0 |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.1.4 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | inotes | 9.0.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.2.2 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | inotes | 8.5.1.2 |
| ibm | inotes | 8.5.1.3 |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.1.4 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | inotes | 9.0.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.2.2 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | inotes | 8.5.1.2 |
| ibm | inotes | 8.5.1.3 |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 115084.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | interact | 8.6 |
| ibm | interact | 9.1.2 |
| ibm | interact | 10.0 |
| ibm | interact | 9.1 |
| ibm | interact | 9.0 |
| ibm | interact | 9.1.1 |
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | interact | 8.6 |
| ibm | interact | 9.1.2 |
| ibm | interact | 10.0 |
| ibm | interact | 9.1 |
| ibm | interact | 9.0 |
| ibm | interact | 9.1.1 |
IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | multi-enterprise_integration_gateway | 1.0.0.1 |
| ibm | b2b_advanced_communications | * |
| ibm | multi-enterprise_integration_gateway | 1.0.0 |
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.1.1 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.1.12 |
| ibm | websphere_commerce | 8.0.1.2 |
| ibm | websphere_commerce | 8.0.0.15 |
| ibm | websphere_commerce | 8.0.0.13 |
| ibm | websphere_commerce | 8.0.0.10 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 8.0.1.8 |
| ibm | websphere_commerce | 8.0.1.0 |
| ibm | websphere_commerce | 7.0.0.8 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 8.0.1.11 |
| ibm | websphere_commerce | 8.0.0.16 |
| ibm | websphere_commerce | 8.0.1.4 |
| ibm | websphere_commerce | 8.0.0.11 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.0.19 |
| ibm | websphere_commerce | 8.0.1.5 |
| ibm | websphere_commerce | 8.0.1.6 |
| ibm | websphere_commerce | 8.0.1.9 |
| ibm | websphere_commerce | 8.0.0.14 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 8.0.1.3 |
| ibm | websphere_commerce | 8.0.0.12 |
| ibm | websphere_commerce | 8.0.1.7 |
| ibm | websphere_commerce | 8.0.0.18 |
| ibm | websphere_commerce | 8.0.0.17 |
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | maximo_for_nuclear_power | 7.6 |
| ibm | maximo_for_oil_and_gas | 7.6 |
| ibm | maximo_for_transportation | 7.6 |
| ibm | maximo_for_aviation | 7.6 |
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the TLS certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience_on_cloud_network_capture_add-on | 16.1.01 |
Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.6.1 |
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_for_government | 7.1 |
| ibm | maximo_for_oil_and_gas | 7.6 |
| ibm | maximo_for_energy_optimization | 7.5 |
| ibm | maximo_for_utilities | 7.6 |
| ibm | maximo_for_utilities | 7.5 |
| ibm | maximo_for_utilities | 7.1 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_for_government | 7.5 |
| ibm | maximo_for_aviation | 7.5 |
| ibm | maximo_for_nuclear_power | 7.1 |
| ibm | maximo_for_transportation | 7.5 |
| ibm | maximo_for_life_sciences | 7.5 |
| ibm | maximo_for_life_sciences | 7.6 |
| ibm | maximo_for_life_sciences | 7.1 |
| ibm | maximo_for_nuclear_power | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_for_transportation | 7.1 |
| ibm | maximo_for_nuclear_power | 7.5 |
| ibm | maximo_for_aviation | 7.1 |
| ibm | maximo_for_energy_optimization | 7.6 |
| ibm | maximo_for_government | 7.6 |
| ibm | maximo_for_oil_and_gas | 7.1 |
| ibm | maximo_for_energy_optimization | 7.1 |
| ibm | maximo_for_transportation | 7.6 |
| ibm | maximo_for_aviation | 7.6 |
| ibm | maximo_for_oil_and_gas | 7.5 |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_asset_management | 7.6.0.2 |
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_space_management | 6.4.0.0 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.0.0 |
| ibm | tivoli_storage_manager_for_space_management | * |
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_web_7.0_firmware | * |
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.12 |
| ibm | financial_transaction_manager | 3.0.0.4 |
| ibm | financial_transaction_manager | 3.0.0.9 |
| ibm | financial_transaction_manager | 3.0.0.7 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 3.0.0.11 |
| ibm | financial_transaction_manager | 3.0.0.3 |
| ibm | financial_transaction_manager | 3.0.0.10 |
| ibm | financial_transaction_manager | 3.0.1.0 |
| ibm | financial_transaction_manager | 3.0.0.2 |
| ibm | financial_transaction_manager | 3.0.0.5 |
| ibm | financial_transaction_manager | 3.0.0.8 |
| ibm | financial_transaction_manager | 3.0.0.6 |
| ibm | financial_transaction_manager | 3.0.0.1 |
| ibm | financial_transaction_manager | 3.0.0.14 |
| ibm | financial_transaction_manager | 3.0.0.13 |
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted password by reading application-trace output.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_space_management | 6.4.0 |
| ibm | tivoli_storage_manager_for_space_management | 6.4.3 |
| ibm | tivoli_storage_manager_for_space_management | 6.3.0 |
| ibm | tivoli_storage_manager_for_space_management | 6.3.2 |
| ibm | tivoli_storage_manager_for_space_management | 6.4.1 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.4 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.3 |
| ibm | tivoli_storage_manager_for_space_management | 6.4.0.0 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.2 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.1 |
| ibm | tivoli_storage_manager_for_space_management | 7.1.0 |
| ibm | tivoli_storage_manager_for_space_management | 6.4.2 |
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | 5.5.0.0 |
| ibm | connections | 4.0 |
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.6 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.3.0.1 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.5 |
| ibm | tivoli_monitoring | 6.3.0.5 |
| ibm | tivoli_monitoring | 6.2.3.3 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.3.0.3 |
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.3.4 |
| ibm | tivoli_monitoring | 6.3.0.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
| ibm | tivoli_monitoring | 6.3.0.4 |
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_fastback | * |
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | dashboard_application_services_hub | 3.1.3 |
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 5.0 |
| ibm | kenexa_lms_on_cloud | 4.2 |
| ibm | kenexa_lms_on_cloud | 4.2.3 |
| ibm | kenexa_lms_on_cloud | 5.1 |
| ibm | kenexa_lms_on_cloud | 4.2.4 |
| ibm | kenexa_lms_on_cloud | 4.1 |
| ibm | kenexa_lms_on_cloud | 4.2.2 |
| ibm | kenexa_lms_on_cloud | 5.2 |
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properties, via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_control | 5.2.5 |
| ibm | spectrum_control | 5.2.1 |
| ibm | spectrum_control | 5.2.6 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.8 |
| ibm | spectrum_control | 5.2.1.1 |
| ibm | spectrum_control | 5.2.3 |
| ibm | spectrum_control | 5.2.4 |
| ibm | spectrum_control | 5.2.4.1 |
| ibm | spectrum_control | 5.2.7 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.0 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | spectrum_control | 5.2.5.1 |
| ibm | spectrum_control | 5.2.7.1 |
| ibm | spectrum_control | 5.2.2 |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.4 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.5 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.7 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.2 |
| ibm | tivoli_storage_productivity_center | 5.2.1 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3 |
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.4 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.5 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.7 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.2 |
| ibm | tivoli_storage_productivity_center | 5.2.1 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3 |
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.4 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.5 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.7 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.2 |
| ibm | tivoli_storage_productivity_center | 5.2.1 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3 |
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.4 |
| ibm | spectrum_control | 5.2.10 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.5 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.7 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.2 |
| ibm | tivoli_storage_productivity_center | 5.2.1 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6 |
| ibm | spectrum_control | 5.2.9 |
| ibm | spectrum_control | 5.2.10.1 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3 |
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.1 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.5 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.4 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3 |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.2 |
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | * |
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | 2.0 |
IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_asset_analyzer | 6.1.0.9 |
| ibm | rational_asset_analyzer | 6.1.0 |
| ibm | rational_asset_analyzer | 6.1.0.4 |
| ibm | rational_asset_analyzer | 6.1.0.6 |
| ibm | rational_asset_analyzer | 6.1.0.3 |
| ibm | rational_asset_analyzer | 6.1.0.8 |
| ibm | rational_asset_analyzer | 6.1.0.2 |
| ibm | rational_asset_analyzer | 6.1.0.5 |
| ibm | rational_asset_analyzer | 6.1.0.7 |
| ibm | rational_asset_analyzer | 6.1.0.1 |
The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 allows remote attackers to conduct SSRF attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-918,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | * |
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | * |
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | * |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager_virtual_appliance | * |
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5978.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to discover component passwords via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5975.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.0a |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | distributed_marketing | 9.1.0.0 |
| ibm | distributed_marketing | 9.1.0.7 |
| ibm | distributed_marketing | 9.1.0.10 |
| ibm | distributed_marketing | 9.1.2.1 |
| ibm | distributed_marketing | 8.6.0.3 |
| ibm | distributed_marketing | 9.1.0.11 |
| ibm | distributed_marketing | 9.1.0.2 |
| ibm | distributed_marketing | 9.1.0.5 |
| ibm | distributed_marketing | 8.6.0.8 |
| ibm | distributed_marketing | 9.1.0.8 |
| ibm | distributed_marketing | 10.0.0.1 |
| ibm | distributed_marketing | 8.6.0.6 |
| ibm | distributed_marketing | 10.0.0.0 |
| ibm | distributed_marketing | 9.1.0.9 |
| ibm | distributed_marketing | 9.1.0.3 |
| ibm | distributed_marketing | 8.6.0.5 |
| ibm | distributed_marketing | 9.1.0.4 |
| ibm | distributed_marketing | 8.6.0.9 |
| ibm | distributed_marketing | 8.6.0.4 |
| ibm | distributed_marketing | 8.6.0.7 |
| ibm | distributed_marketing | 8.6.0.0 |
| ibm | distributed_marketing | 9.1.2.2 |
| ibm | distributed_marketing | 8.6.0.2 |
| ibm | distributed_marketing | 9.1.2.3 |
| ibm | distributed_marketing | 9.1.0.6 |
| ibm | distributed_marketing | 8.6.0.10 |
| ibm | distributed_marketing | 9.1.2.0 |
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.5.1.0 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine) through 4.0.2.14-P8AE-IF001, when RegExpSecurityFilter and ScriptSecurityFilter are misconfigured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace | * |
| ibm | filenet_workplace_xt | * |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 8.5.5.10 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 9.0.0.1 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 6.3.0.0 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 7.1.0.0 |
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.6 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 8.5.5.10 |
| ibm | websphere_application_server | 7.0.0.7 |
| ibm | websphere_application_server | 7.0.0.8 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 9.0.0.1 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.5 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.41 |
| ibm | websphere_application_server | 7.0.0.39 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 8.0.0.2 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.9 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 7.0.0.28 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 7.0.0.4 |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive information via a crafted HTTP request that triggers construction of a runtime error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 7.1.1.13 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.3 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.1.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available to an authenticated user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.1 |
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect:direct | 4.6 |
| ibm | sterling_connect:direct | 4.5.01 |
| ibm | sterling_connect:direct | 4.7 |
| ibm | sterling_connect:direct | 4.5 |
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to cause a denial of service via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_connect:direct | 4.6 |
| ibm | sterling_connect:direct | 4.5.01 |
| ibm | sterling_connect:direct | 4.7 |
| ibm | sterling_connect:direct | 4.5 |
IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.5 |
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length restrictions, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-640,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-640,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | * |
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 9.0.1 |
| ibm | tealeaf_customer_experience | 9.0.1a |
| ibm | tealeaf_customer_experience | 9.0.0 |
| ibm | tealeaf_customer_experience | 9.0.2a |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.5.1.0 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.
CVSS 2.0
Severity: LOW
Problem Type: CWE-918,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | forms_experience_builder | 8.5.1 |
| ibm | forms_experience_builder | 8.6.0 |
| ibm | forms_experience_builder | 8.5 |
IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks. IBM X-Force ID: 116738.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_contract_management | 10.0.1.4 |
| ibm | emptoris_contract_management | 10.0.2.13 |
| ibm | emptoris_contract_management | 10.0.2.9 |
| ibm | emptoris_contract_management | 10.0.2.5 |
| ibm | emptoris_contract_management | 10.0.2.11 |
| ibm | emptoris_contract_management | 10.0.0.1 |
| ibm | emptoris_contract_management | 10.0.1.2 |
| ibm | emptoris_contract_management | 10.0.2.8 |
| ibm | emptoris_contract_management | 10.0.0.0 |
| ibm | emptoris_contract_management | 10.0.1.0 |
| ibm | emptoris_contract_management | 10.0.2.17 |
| ibm | emptoris_contract_management | 10.0.2.15 |
| ibm | emptoris_contract_management | 10.0.2.2 |
| ibm | emptoris_contract_management | 10.0.2.3 |
| ibm | emptoris_contract_management | 10.0.1.5 |
| ibm | emptoris_contract_management | 10.0.4.0 |
| ibm | emptoris_contract_management | 10.0.2.14 |
| ibm | emptoris_contract_management | 10.0.2.16 |
| ibm | emptoris_contract_management | 10.0.1.1 |
| ibm | emptoris_contract_management | 10.0.2.1 |
| ibm | emptoris_contract_management | 10.0.2.0 |
| ibm | emptoris_contract_management | 10.0.1.3 |
| ibm | emptoris_contract_management | 10.0.2.7 |
| ibm | emptoris_contract_management | 10.0.2.6 |
| ibm | emptoris_contract_management | 10.0.2.10 |
| ibm | emptoris_contract_management | 10.0.2.12 |
| ibm | emptoris_contract_management | 10.1.0.0 |
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.12 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2.6 |
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.2.1 |
| ibm | sterling_b2b_integrator | 5.2.5 |
| ibm | sterling_b2b_integrator | 5.2.4.2 |
| ibm | sterling_b2b_integrator | 5.2.4 |
| ibm | sterling_b2b_integrator | 5.2.2 |
| ibm | sterling_b2b_integrator | 5.2.4.1 |
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116755.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.4.2.0 |
| ibm | sterling_secure_proxy | 3.4.3.0 |
IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 6.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.4.2.0 |
| ibm | sterling_secure_proxy | 3.4.3.0 |
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.4.2.0 |
| ibm | sterling_secure_proxy | 3.4.3.0 |
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_secure_proxy | 3.4.2.0 |
| ibm | sterling_secure_proxy | 3.4.3.0 |
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 116881.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995545.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.3 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.6 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.4.0 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.0.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6.3 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.0 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.4.1 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.4 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.4 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.1 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.4.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.6.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.3 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.1 |
| ibm | tivoli_storage_flashcopy_manager_for_vmware | 4.1.2 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6.2 |
IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.3 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.4.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6.3 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.4 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.6.2 |
IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116896.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 116918.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_team_concert | 5.0.1 |
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to execute arbitrary code on the system in the same context as the victim.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.1.1 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 9.0.3.0 |
| ibm | security_appscan | 9.0.3.1 |
| ibm | security_appscan | 9.0.2.0 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 9.0.2.1 |
Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to session expiration not being enforced.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.4.2.2 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 6.4.2.4 |
| ibm | tivoli_storage_manager | 6.4.2.3 |
| ibm | tivoli_storage_manager | 6.4.1.1 |
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.4.2.2 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 6.4.2.4 |
| ibm | tivoli_storage_manager | 6.4.2.3 |
| ibm | tivoli_storage_manager | 6.4.1.1 |
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.4.2.2 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 6.4.2.4 |
| ibm | tivoli_storage_manager | 6.4.2.3 |
| ibm | tivoli_storage_manager | 6.4.1.1 |
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.4.2.2 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.4.2.1 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 6.4.2.4 |
| ibm | tivoli_storage_manager | 6.4.2.3 |
| ibm | tivoli_storage_manager | 6.4.1.1 |
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.2 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000442.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | call_center_for_commerce | 9.3 |
| ibm | call_center_for_commerce | 9.4 |
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_datastage | 11.3 |
| ibm | infosphere_datastage | 11.3.1 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_datastage | 11.5 |
| ibm | infosphere_information_server | 11.3.1 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference#: 213457065.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | resilient | 26.0 |
| ibm | resilient | 26.1 |
| ibm | resilient | 26.2 |
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 8.2 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 9.5 |
IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_asset_management_for_it | - |
| ibm | maximo_for_life_sciences | - |
| ibm | smartcloud_control_desk | - |
| ibm | tivoli_change_and_configuration_management_database | - |
| ibm | maximo_for_nuclear_power | - |
| ibm | maximo_for_aviation | - |
| ibm | tivoli_service_request_manager | - |
| ibm | maximo_for_transportation | - |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_for_oil_and_gas | - |
| ibm | tivoli_integration_composer | - |
| ibm | maximo_for_utilities | - |
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_disclosure_management | 10.2.4 |
| ibm | cognos_disclosure_management | 10.2.3 |
| ibm | cognos_disclosure_management | 10.2.1 |
| ibm | cognos_disclosure_management | 10.2.2 |
| ibm | cognos_disclosure_management | 10.2.6 |
| ibm | cognos_disclosure_management | 10.2.0 |
| ibm | cognos_disclosure_management | 10.2.5 |
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | vios | 2.2.5.0 |
| ibm | vios | 2.2.2.6 |
| ibm | vios | 2.2.3.70 |
| ibm | vios | 2.2.2.2 |
| ibm | aix | 5.3 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.4.30 |
| ibm | vios | 2.2.4.0 |
| ibm | vios | 2.2.3.80 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.0.0 |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | vios | 2.2.2.70 |
| ibm | vios | 2.2.4.22 |
| ibm | vios | 2.2.3.52 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.5.10 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.3.50 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.3.51 |
| ibm | vios | 2.2.3.60 |
| ibm | vios | 2.2.4.10 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.4.21 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
| ibm | vios | 2.2.4.23 |
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-416,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.5 |
| ibm | tivoli_monitoring | 6.3.0.5 |
| ibm | tivoli_monitoring | 6.2.3.3 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.3.0.4 |
| ibm | tivoli_monitoring | 6.2.3.0 |
| ibm | tivoli_monitoring | 6.3.0.6 |
| ibm | tivoli_monitoring | 6.3.0.1 |
| ibm | tivoli_monitoring | 6.3.0.3 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.3.4 |
| ibm | tivoli_monitoring | 6.3.0.2 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.2.0 |
| ibm | tivoli_monitoring | 6.2.2.1 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.0 |
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.0 |
IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 8.5.1.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.5 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.3 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | domino | 8.5.2.0 |
| ibm | domino | 8.5.2.3 |
| ibm | domino | 9.0.0.0 |
| ibm | domino | 8.5.3.2 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.1.4 |
| ibm | domino | 8.5.3.3 |
| ibm | domino | 9.0.1.7 |
| ibm | domino | 8.5.2.4 |
| ibm | domino | 8.5.1.0 |
| ibm | domino | 9.0.1.6 |
| ibm | domino | 8.5.1.3 |
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.0.0 |
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | * |
| ibm | websphere_commerce | 8.0.3.0 |
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_key_lifecycle_manager | 2.0.1.4 |
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.8 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.6 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.0 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.3 |
| ibm | tivoli_key_lifecycle_manager | 2.0.1.5 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000771.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | disposal_and_governance_management_for_it | 6.0.3.1 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.1 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.7 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.0 |
| ibm | global_retention_policy_and_schedule_management | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.6 |
| ibm | global_retention_policy_and_schedule_management | 6.0.3.1 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.1 |
| ibm | global_retention_policy_and_schedule_management | 6.0.3.4 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.5 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.3 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.0 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.5 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.4 |
| ibm | disposal_and_governance_management_for_it | 6.0.3 |
| ibm | disposal_and_governance_management_for_it | 6.0.3.2 |
| ibm | disposal_and_governance_management_for_it | 6.0 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.7 |
| ibm | global_retention_policy_and_schedule_management | 6.0 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.6 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.3 |
| ibm | global_retention_policy_and_schedule_management | 6.0.3.3 |
| ibm | disposal_and_governance_management_for_it | 6.0.3.3 |
| ibm | disposal_and_governance_management_for_it | 6.0.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.3.2 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.4 |
| ibm | disposal_and_governance_management_for_it | 6.0.1.3 |
| ibm | disposal_and_governance_management_for_it | 6.0.3.4 |
| ibm | global_retention_policy_and_schedule_management | 6.0.1.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | * |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 7.1.0.0 |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | 7.1.0.0 |
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | distributed_marketing | 9.1.0.0 |
| ibm | marketing_operations | 10.0.0.0 |
| ibm | distributed_marketing | 10.0.0.0 |
| ibm | marketing_platform | 10.0 |
| ibm | distributed_marketing | 9.0.0.0 |
| ibm | marketing_operations | 8.6.0.0 |
| ibm | marketing_operations | 9.1.0.0 |
| ibm | marketing_platform | 9.0.0.0 |
| ibm | distributed_marketing | 8.6.0.0 |
| ibm | marketing_platform | 8.6.0.0 |
| ibm | marketing_platform | 9.1.2.0 |
| ibm | marketing_platform | 9.1.0.0 |
| ibm | marketing_operations | 9.0.0.0 |
IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | domino | 8.5.1.5 |
| ibm | domino | 8.5.1.2 |
| ibm | domino | 8.5.2.1 |
| ibm | domino | 9.0.1.1 |
| ibm | domino | 8.5.3.0 |
| ibm | domino | 8.5.3.1 |
| ibm | domino | 9.0.1.4 |
| ibm | domino | 9.0.1.0 |
| ibm | domino | 8.5.3.4 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1.4 |
| ibm | domino | 8.5.2.3 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.2.2 |
| ibm | domino | 8.5.1.0 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | domino | 8.5.1.3 |
| ibm | inotes | 8.5.1.3 |
| ibm | domino | 8.5.1.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | domino | 8.5.3.5 |
| ibm | domino | 9.0.1.5 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | domino | 9.0.1.2 |
| ibm | domino | 9.0.1.3 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | domino | 8.5.2.0 |
| ibm | inotes | 8.5.3.0 |
| ibm | domino | 9.0.0.0 |
| ibm | inotes | 9.0.1.1 |
| ibm | domino | 8.5.3.2 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | domino | 8.5.2.2 |
| ibm | domino | 8.5.3.3 |
| ibm | inotes | 9.0.1.4 |
| ibm | domino | 8.5.2.4 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | domino | 9.0.1.6 |
| ibm | inotes | 8.5.1.2 |
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118352.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 4.2.0.2 |
| ibm | spectrum_scale | 4.1.0.0 |
| ibm | spectrum_scale | 4.1.1.6 |
| ibm | spectrum_scale | 4.2.0.0 |
| ibm | general_parallel_file_system | 4.1.0.2 |
| ibm | general_parallel_file_system | 4.1.0.0 |
| ibm | general_parallel_file_system | 4.1.0.8 |
| ibm | general_parallel_file_system | 4.1.0.1 |
| ibm | spectrum_scale | 4.1.1.7 |
| ibm | spectrum_scale | 4.2.1 |
| ibm | general_parallel_file_system | 4.1.0.3 |
| ibm | spectrum_scale | 4.1.1.3 |
| ibm | spectrum_scale | 4.1.1.1 |
| ibm | spectrum_scale | 4.1.1.8 |
| ibm | general_parallel_file_system | 4.1.0.4 |
| ibm | spectrum_scale | 4.1.1.10 |
| ibm | spectrum_scale | 4.1.1.4 |
| ibm | spectrum_scale | 4.1.1.5 |
| ibm | general_parallel_file_system | 4.1.0.7 |
| ibm | spectrum_scale | 4.2.2.0 |
| ibm | spectrum_scale | 4.2.0.3 |
| ibm | spectrum_scale | 4.1.1.0 |
| ibm | spectrum_scale | 4.1.1.2 |
| ibm | spectrum_scale | 4.1.1.9 |
| ibm | general_parallel_file_system | 4.1.0.6 |
| ibm | general_parallel_file_system | 4.1.0.5 |
| ibm | spectrum_scale | 4.2.0.1 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118356.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.1.1.11 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118383.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.6 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | advanced_management_module_firmware | - |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
CVSS 2.0
Severity: LOW
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.6.3 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 7.1.6.4 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 7.1.6.2 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.4.0.0 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | 9.4.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.5.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.1 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 10.0 |
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5.5 |
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms_on_cloud | 13.2.3 |
| ibm | kenexa_lms_on_cloud | 13.2.2 |
| ibm | kenexa_lms_on_cloud | 13.2.4 |
| ibm | kenexa_lms_on_cloud | 13.2 |
| ibm | kenexa_lms_on_cloud | 13.1 |
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_workplace_xt | 1.1.5 |
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | web_content_manager_production_analytics | 4.0 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 8.5 |
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.5 |
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.5 |
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118540.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.4 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.1 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.3 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.0 |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2.5 |
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 5.1 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 5.2 |
| ibm | kenexa_lms | 4.2.4 |
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.8 |
| ibm | websphere_application_server | 9.0.0.2 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.9 |
| ibm | websphere_application_server | 8.5.5.7 |
| ibm | websphere_application_server | 8.5.5.6 |
| ibm | websphere_application_server | 8.5.5.11 |
| ibm | websphere_application_server | 8.5.5.10 |
| ibm | websphere_application_server | 9.0.0.1 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| ibm | websphere_application_server | 8.5.5.5 |
| ibm | websphere_application_server | 8.5.5.1 |
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lms | 4.2.3 |
| ibm | kenexa_lms | 4.2 |
| ibm | kenexa_lms | 5.0 |
| ibm | kenexa_lms | 4.2.2 |
| ibm | kenexa_lms | 4.1 |
| ibm | kenexa_lms | 4.2.4 |
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | social_rendering_templates_for_digital_data_connector | 1.0 |
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.7.100 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 7.1.7.200 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 8.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 8.1.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.3.6.100 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 8.1.1 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.7.100 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 7.1.7.200 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 8.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 8.1.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.3.6.100 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 8.1.1 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.2.0 |
| ibm | spectrum_control | 5.2.10 |
| ibm | tivoli_storage_productivity_center | 5.2.4.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.0 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3.0 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0.0 |
| ibm | spectrum_control | 5.2.11 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | spectrum_control | 5.2.9 |
| ibm | tivoli_storage_productivity_center | 5.2.1.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.7.0 |
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
CVSS 2.0
Severity: LOW
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.2.0 |
| ibm | spectrum_control | 5.2.10 |
| ibm | tivoli_storage_productivity_center | 5.2.4.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.0 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3.0 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0.0 |
| ibm | spectrum_control | 5.2.11 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | spectrum_control | 5.2.9 |
| ibm | tivoli_storage_productivity_center | 5.2.1.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1_+ |
| ibm | tivoli_storage_productivity_center | 5.2.7.0 |
IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_productivity_center | 5.2.2.0 |
| ibm | spectrum_control | 5.2.10 |
| ibm | tivoli_storage_productivity_center | 5.2.4.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.0 |
| ibm | spectrum_control | 5.2.8 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1 |
| ibm | tivoli_storage_productivity_center | 5.2.3.0 |
| ibm | tivoli_storage_productivity_center | 5.2.7.1 |
| ibm | tivoli_storage_productivity_center | 5.2.6.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0.0 |
| ibm | spectrum_control | 5.2.11 |
| ibm | tivoli_storage_productivity_center | 5.2.1.1 |
| ibm | spectrum_control | 5.2.9 |
| ibm | tivoli_storage_productivity_center | 5.2.1.0 |
| ibm | tivoli_storage_productivity_center | 5.2.0 |
| ibm | tivoli_storage_productivity_center | 5.2.5.1 |
| ibm | tivoli_storage_productivity_center | 5.2.4.1_+ |
| ibm | tivoli_storage_productivity_center | 5.2.7.0 |
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 7.1 |
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118833.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118834
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118835.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118836.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.6 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118837.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. IBM X-Force ID: 118838.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.12 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118839.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.12 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118840.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | dashdb_local | 1.1.0 |
| ibm | dashdb_local | 1.2.1 |
| ibm | dashdb_local | 1.3.0 |
| ibm | dashdb_local | 1.0.0 |
| ibm | dashdb_local | 1.3.1 |
| ibm | dashdb_local | 1.1.1 |
| ibm | dashdb_local | 1.2.0 |
IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | * |
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_inventory | * |
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | * |
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_inventory | * |
| ibm | license_metric_tool | * |
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | 9.2 |
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | 9.2 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998515.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | vios | 2.2.5.0 |
| ibm | vios | 2.2.2.6 |
| ibm | vios | 2.2.3.70 |
| ibm | vios | 2.2.2.2 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.4.30 |
| ibm | vios | 2.2.4.0 |
| ibm | vios | 2.2.3.80 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.0.0 |
| ibm | vios | 2.2.3.4 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.2.1 |
| ibm | vios | 2.2.2.70 |
| ibm | vios | 2.2.4.22 |
| ibm | vios | 2.2.3.52 |
| ibm | aix | 6.1 |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.5.10 |
| ibm | vios | 2.2.3.3 |
| ibm | aix | 7.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.3.50 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.3.51 |
| ibm | vios | 2.2.3.60 |
| ibm | vios | 2.2.4.10 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.4.21 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.2.3 |
| ibm | vios | 2.2.4.23 |
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997798.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118912.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rhapsody_design_manager | 6.0.3 |
| ibm | rhapsody_design_manager | 6.0.1 |
| ibm | rhapsody_design_manager | 6.0.2 |
| ibm | rhapsody_design_manager | 5.0.2 |
| ibm | rhapsody_design_manager | 6.0 |
| ibm | rhapsody_design_manager | 5.0 |
| ibm | rhapsody_design_manager | 5.0.1 |
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | 9.2 |
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | 9.2 |
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | license_metric_tool | 9.2.0 |
| ibm | bigfix_inventory | 9.2 |
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_datastage | 11.3 |
| ibm | infosphere_datastage | 9.1 |
| ibm | infosphere_datastage | 8.7 |
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_datastage | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_datastage | 9.1 |
| ibm | infosphere_datastage | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_datastage | 8.7 |
| ibm | infosphere_information_server | 8.7 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_datastage | 11.3 |
| ibm | infosphere_datastage | 9.1 |
| ibm | infosphere_datastage | 11.5 |
| ibm | infosphere_datastage | 8.7 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_storage_ts3100-ts3200_tape_library | * |
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.2.3.1 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.2.1.2 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.2.3.0 |
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.2 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.1.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.14 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.1.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM Reference #: 1997906.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | integration_bus | 9.0 |
| ibm | integration_bus | 10.0 |
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 119515.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_cast_iron_solution | 7.5.0.0 |
| ibm | websphere_cast_iron_solution | 7.5.0.1 |
| ibm | websphere_cast_iron_solution | 7.5.1.0 |
| ibm | websphere_cast_iron_solution | 7.0.0 |
| ibm | websphere_cast_iron_solution | 7.0.0.2 |
| ibm | websphere_cast_iron_solution | 7.0.0.1 |
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_cast_iron_solution | 7.5.0.0 |
| ibm | websphere_cast_iron_solution | 7.5.0.1 |
| ibm | websphere_cast_iron_solution | 7.5.1.0 |
| ibm | websphere_cast_iron_solution | 7.0.0 |
| ibm | websphere_cast_iron_solution | 7.0.0.2 |
| ibm | websphere_cast_iron_solution | 7.0.0.1 |
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | websphere | 7.2.0.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere | 7.2.0.4 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere | 7.2.0.1 |
| ibm | websphere | 7.2.0.3 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | websphere | 7.2.0.5 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | websphere | 7.2 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999960.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Reference #: 1999960.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and the browser. IBM Reference #: 1999960.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_doors_next_generation | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119529.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.1.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.4 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager_virtual_appliance | 7.0.1.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.4 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.0 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.2 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.1 |
| ibm | security_identity_manager_virtual_appliance | 7.0.1.3 |
| ibm | security_identity_manager_virtual_appliance | 7.0.0.0 |
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | 8.0 |
| ibm | integration_bus | 9.0 |
| ibm | integration_bus | 10.0 |
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence_server | 10.2.1.1 |
| ibm | cognos_business_intelligence_server | 10.2.0 |
| ibm | cognos_business_intelligence_server | 10.2.1 |
| ibm | cognos_business_intelligence_server | 10.2.2 |
| ibm | cognos_business_intelligence_server | 10.1.1 |
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.0 |
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 119733.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999537.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.7.0 |
IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119761.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.0.4.9 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119762.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1996200.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0.1.0 |
| ibm | security_identity_manager | 7.0.1.1 |
| ibm | security_identity_manager | 7.0.1.4 |
| ibm | security_identity_manager | 7.0.0.1 |
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_identity_manager | 7.0.0.3 |
| ibm | security_identity_manager | 7.0.1.2 |
| ibm | security_identity_manager | 7.0.0.2 |
| ibm | security_identity_manager | 7.0.1.3 |
IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119821.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 5.0.1 |
IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | 9.1.0.1 |
| ibm | campaign | 9.1.0.5 |
| ibm | campaign | 10.0.0.1 |
| ibm | campaign | 10.0.0.2 |
| ibm | campaign | 9.1.0.2 |
| ibm | campaign | 9.1.2.2 |
| ibm | campaign | 9.1.0.4 |
| ibm | campaign | 9.1.0.11 |
| ibm | campaign | 10.1 |
| ibm | campaign | 9.1.0.6 |
| ibm | campaign | 9.1.0.7 |
| ibm | campaign | 9.1.0.9 |
| ibm | campaign | 10.0.0.0 |
| ibm | campaign | 9.1.0.10 |
| ibm | campaign | 9.1.0.8 |
| ibm | campaign | 9.1.0.3 |
| ibm | campaign | 9.1.2.3 |
| ibm | campaign | 9.1.0.12 |
| ibm | campaign | 9.1.2.0 |
| ibm | campaign | 9.1.2.1 |
| ibm | campaign | 9.1.2.4 |
| ibm | campaign | 9.1.0.0 |
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-417,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.5.7 |
| vmware | spring_security | 3.2.8 |
| vmware | spring_security | 3.2.0 |
| vmware | spring_security | 4.1.2 |
| vmware | spring_security | 4.2.0 |
| ibm | websphere_application_server | 8.5.5.5 |
| vmware | spring_security | 3.2.7 |
| vmware | spring_security | 3.2.9 |
| ibm | websphere_application_server | 8.5.5.8 |
| vmware | spring_security | 4.1.3 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.5.9 |
| vmware | spring_security | 3.2.4 |
| vmware | spring_security | 3.2.5 |
| ibm | websphere_application_server | 8.5.5.6 |
| vmware | spring_security | 3.2.3 |
| vmware | spring_security | 3.2.1 |
| vmware | spring_security | 3.2.2 |
| vmware | spring_security | 3.2.6 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
| vmware | spring_security | 4.1.1 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.5.1 |
| vmware | spring_security | 4.1.0 |
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1998714.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | dashboard_application_services_hub | 3.1.3 |
| ibm | dashboard_application_services_hub | 3.1.2.1 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
| ibm | maximo_asset_management_essentials | 7.1 |
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_appscan | 9.0.1.0 |
| ibm | security_appscan | 9.0.1.1 |
| ibm | security_appscan | 9.0.0.0 |
| ibm | security_appscan | 9.0.3.0 |
| ibm | security_appscan | 9.0.3.5 |
| ibm | security_appscan | 9.0.3.1 |
| ibm | security_appscan | 9.0.2.0 |
| ibm | security_appscan | 9.0.0.1 |
| ibm | security_appscan | 9.0.3.4 |
| ibm | security_appscan | 9.0.2.1 |
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5 |
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.1.1 |
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.1.4 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | inotes | 9.0.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.0.1 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.2.2 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | inotes | 8.5.1.2 |
| ibm | inotes | 8.5.1.3 |
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_selling_and_fulfillment_foundation | 9.4.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.5.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.1 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.3.0 |
| ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.1 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 9.0 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_open_admin_tool | 11.5 |
| ibm | informix_open_admin_tool | 12.1 |
| ibm | informix_open_admin_tool | 11.7 |
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 120657.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.12 |
| ibm | emptoris_strategic_supply_management | 10.1.1.12 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.1.1.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.13 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.10 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.12 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.9 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.8 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.13 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.11 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.5 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.6 |
| ibm | emptoris_supplier_lifecycle_management | 10.1.0.7 |
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_engineering_lifecycle_manager | 4.0.1 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120661.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120662.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120663.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_quality_manager | 4.0.0 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120666.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.1 |
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | data_server_runtime_client | - |
| ibm | db2_connect | 10.1 |
| ibm | data_server_client | - |
| ibm | db2 | 9.7 |
| ibm | data_server_driver_for_odbc_and_cli | - |
| ibm | data_server_driver_package | - |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.0.4.9 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 5.2 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.0 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.0.4.9 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121151.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 6.0.0 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_team_concert | 4.0.0 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_team_concert | 6.0.2 |
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | 10.0 |
| ibm | campaign | 9.1 |
| ibm | campaign | 9.1.2 |
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.
CVSS 2.0
Severity: LOW
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | 10.0 |
| ibm | campaign | 9.1 |
| ibm | campaign | 9.1.2 |
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | 10.0 |
| ibm | campaign | 8.6 |
| ibm | campaign | 9.1 |
| ibm | campaign | 9.1.1 |
| ibm | campaign | 9.1.2 |
| ibm | campaign | 9.0 |
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.0.0 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 8.0.0.2 |
IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_internet_pass-thru | 2.1 |
| ibm | websphere_mq_internet_pass-thru | 2.0 |
IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use this information to launch further attacks against the affected system. IBM X-Force ID: 121171.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_operations | * |
| ibm | marketing_operations | 10.1 |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.5 |
IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
| ibm | websphere_application_server | 8.5.5 |
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 8.2 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 9.5 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.1.1.9 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management | 7.1.1.10 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management | 7.1.1.1 |
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.1.1.12 |
| ibm | maximo_asset_management | 7.1.1.3 |
| ibm | maximo_asset_management | 7.6.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.1.1.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management | 7.1.1.2 |
| ibm | maximo_asset_management | 7.1.1.6 |
| ibm | maximo_asset_management | 7.1.1.5 |
| ibm | maximo_asset_management | 7.1.1.11 |
| ibm | maximo_asset_management | 7.1.2 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management | 7.1.1 |
| ibm | maximo_asset_management | 7.1.1.8 |
| ibm | maximo_asset_management | 7.5.0.8 |
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence_server | 10.2.1.1 |
| ibm | cognos_business_intelligence_server | 10.2.0 |
| ibm | cognos_business_intelligence_server | 10.2.1 |
| ibm | cognos_business_intelligence_server | 10.2.2 |
| ibm | cognos_business_intelligence_server | 10.1.1 |
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 10.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | integration_bus | 10.0.0.0 |
| ibm | integration_bus | 10.0.0.7 |
| ibm | integration_bus | 9.0.0.0 |
| ibm | integration_bus | 10.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.7 |
| ibm | integration_bus | 9.0.0.8 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 9.0.0.7 |
| ibm | integration_bus | 10.0.0.6 |
| ibm | integration_bus | 10.0.0.5 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.6 |
| ibm | integration_bus | 10.0.0.9 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.0 |
| ibm | integration_bus | 10.0.0.8 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 9.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.8 |
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_requirements_composer | 4.0.0.1 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.0 |
| ibm | rational_requirements_composer | 4.0.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 9.0.1.1 |
| ibm | expeditor | 6.2.1 |
| ibm | inotes | 9.0.1.8 |
| ibm | inotes | 9.0.0.0 |
| ibm | expeditor | 6.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | expeditor | 6.2.2 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.2.4 |
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 9.0.1.8 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.2.4 |
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121418.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.6 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.2 |
| ibm | qradar_incident_forensics | 7.2.5 |
| ibm | qradar_incident_forensics | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_incident_forensics | 7.2.4 |
| ibm | qradar_incident_forensics | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_incident_forensics | 7.2.7 |
IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_hardware_management_console | 3.3.2 |
| ibm | power_hardware_management_console | 4.1 |
IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
| ibm | websphere_application_server | 8.5.5 |
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 8.5.0.2 |
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | insights_foundation_for_energy | 1.0 |
| ibm | insights_foundation_for_energy | 1.6 |
| ibm | insights_foundation_for_energy | 1.5 |
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM Reference #: 1998874.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.3 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kenexa_lcms_premier | 9.5 |
| ibm | kenexa_lcms_premier | 10.2 |
| ibm | kenexa_lcms_premier | 10.0 |
| ibm | kenexa_lcms_premier | 10.3 |
| ibm | kenexa_lcms_premier | 9.2 |
| ibm | kenexa_lcms_premier | 9.2.1 |
| ibm | kenexa_lcms_premier | 9.3 |
| ibm | kenexa_lcms_premier | 9.1 |
| ibm | kenexa_lcms_premier | 9.4 |
IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.
CVSS 2.0
Severity: LOW
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 10.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | integration_bus | 9.0 |
| ibm | integration_bus | 10.0.0.7 |
| ibm | integration_bus | 10.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.7 |
| ibm | websphere_message_broker | 8.0 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 9.0.0.7 |
| ibm | integration_bus | 10.0.0.6 |
| ibm | integration_bus | 10.0.0.5 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.6 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 10.0 |
| ibm | integration_bus | 9.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.8 |
IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-404,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.6 |
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999736.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 2.0.3 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122200.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.0.1.3 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.0.1.4 |
| ibm | urbancode_deploy | 6.0.1.7 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1 |
| ibm | urbancode_deploy | 6.0.1.0 |
| ibm | urbancode_deploy | 6.0.1.13 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.0.1.5 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.0.1.6 |
| ibm | urbancode_deploy | 6.0.1.11 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.0.1.8 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.0.1.9 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.0.1.10 |
| ibm | urbancode_deploy | 6.0.1.12 |
| ibm | urbancode_deploy | 6.0.1.2 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.0.1.1 |
| ibm | urbancode_deploy | 6.0 |
| ibm | urbancode_deploy | 6.2.0.201 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
CVSS 2.0
Severity: LOW
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
| ibm | websphere_application_server | 8.5.5 |
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.1.0 |
IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have access to. IBM Reference #: 1999563.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 5.1.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | algo_one | 5.1.0 |
| ibm | algo_one | 4.9.1 |
| ibm | algo_one | 5.0.0 |
IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force. ID: 122592
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.5 |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 5.0 |
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 122891.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.12 |
| ibm | financial_transaction_manager | 3.0.0.4 |
| ibm | financial_transaction_manager | 3.0.0.9 |
| ibm | financial_transaction_manager | 3.0.0.7 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 3.0.0.11 |
| ibm | financial_transaction_manager | 3.0.0.3 |
| ibm | financial_transaction_manager | 3.0.0.10 |
| ibm | financial_transaction_manager | 3.0.0.2 |
| ibm | financial_transaction_manager | 3.0.0.5 |
| ibm | financial_transaction_manager | 3.0.0.8 |
| ibm | financial_transaction_manager | 3.0.0.6 |
| ibm | financial_transaction_manager | 3.0.0.1 |
| ibm | financial_transaction_manager | 3.0.0.15 |
| ibm | financial_transaction_manager | 3.0.0.14 |
| ibm | financial_transaction_manager | 3.0.0.13 |
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.6.0 |
IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123036.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123187.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123188.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.1.1 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.3.2 |
| ibm | websphere_commerce | 8.0.1.2 |
| ibm | websphere_commerce | 8.0.3.3 |
| ibm | websphere_commerce | 8.0.0.15 |
| ibm | websphere_commerce | 8.0.0.13 |
| ibm | websphere_commerce | 8.0.0.10 |
| ibm | websphere_commerce | 8.0.1.8 |
| ibm | websphere_commerce | 8.0.1.0 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 8.0.3.0 |
| ibm | websphere_commerce | 8.0.0.16 |
| ibm | websphere_commerce | 8.0.3.1 |
| ibm | websphere_commerce | 8.0.1.4 |
| ibm | websphere_commerce | 8.0.0.11 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.1.5 |
| ibm | websphere_commerce | 8.0.1.6 |
| ibm | websphere_commerce | 8.0.1.9 |
| ibm | websphere_commerce | 8.0.0.14 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 8.0.1.3 |
| ibm | websphere_commerce | 8.0.0.12 |
| ibm | websphere_commerce | 8.0.1.7 |
| ibm | websphere_commerce | 8.0.0.17 |
The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management | 7.1.1 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management | 7.1.1 |
IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123429.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_compliance | * |
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_security_compliance_analytics | 1.9.70 |
IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_security_compliance_analytics | 1.9.70 |
The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.5.1.0 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.
CVSS 2.0
Severity: LOW
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.3.5 |
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.3.5 |
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.3.5 |
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 6.1.0.3 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 6.1.5.2 |
| ibm | websphere_portal | 6.1.0.2 |
| ibm | websphere_portal | 6.1.0.4 |
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 6.1.5.0 |
| ibm | websphere_portal | 6.1.0.6 |
| ibm | websphere_portal | 6.1.5.3 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 6.1.0.1 |
| ibm | websphere_portal | 6.1.5.1 |
| ibm | websphere_portal | 6.1.0.5 |
| ibm | websphere_portal | 6.1.0.0 |
IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary code on the system. By manipulating a configurable property, an attacker could exploit this vulnerability to gain full control over the system. IBM X-Force ID: 123559.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access. IBM X-Force ID: 123661.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.4.8 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.0.4.9 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.0.4.0 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 6.0.4.5 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.0.4.7 |
| ibm | curam_social_program_management | 6.0.4.3 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 6.0.4.4 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.0.4.1 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.0.4.2 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.0.4.6 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_security_compliance_analytics | 1.9.70 |
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 123672.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-307,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_security_compliance_analytics | 1.9.70 |
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_compliance | * |
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 |
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_compliance | * |
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: 123676.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_security_compliance_analytics | 1.9.79 |
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 123677.
CVSS 2.0
Severity: LOW
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_compliance | * |
IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123678.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2.2 |
| ibm | bigfix_platform | 9.2.0 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.1.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.2.1 |
| ibm | bigfix_platform | 9.1.3 |
| ibm | bigfix_platform | 9.1.6 |
| ibm | bigfix_platform | 9.2.4 |
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5.6 |
| ibm | bigfix_platform | 9.2.5 |
| ibm | bigfix_platform | 9.1.4 |
| ibm | bigfix_platform | 9.1.5 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.3 |
| ibm | bigfix_platform | 9.5.5 |
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM Platform LSF 10.1 contains an unspecified vulnerability that could allow a local user to escalate their privileges and obtain root access. IBM X-Force ID: 123741.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_lsf | 9.1.1 |
| ibm | spectrum_lsf | 9.1.2 |
| ibm | spectrum_lsf | 8.3 |
| ibm | spectrum_lsf | 9.1.3 |
| ibm | spectrum_lsf | 10.1.0.1 |
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 10.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.4 |
| ibm | integration_bus | 10.0.0.7 |
| ibm | integration_bus | 10.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.7 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 9.0.0.7 |
| ibm | integration_bus | 10.0.0.6 |
| ibm | integration_bus | 10.0.0.5 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | websphere_message_broker | 8.0.0.6 |
| ibm | integration_bus | 9.0.0 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | websphere_message_broker | 8.0.0.0 |
| ibm | integration_bus | 10.0.0 |
| ibm | websphere_message_broker | 8.0.0.3 |
| ibm | websphere_message_broker | 8.0.0.2 |
| ibm | integration_bus | 9.0.0.6 |
| ibm | websphere_message_broker | 8.0.0.5 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | websphere_message_broker | 8.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.1 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management | 7.1.1 |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123849.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 5.0.0 |
| ibm | daeja_viewone | 5.0.2 |
| ibm | daeja_viewone | 4.1.5.1 |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 5.0.0 |
| ibm | daeja_viewone | 5.0.2 |
| ibm | daeja_viewone | 4.1.5.1 |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 5.0.0 |
| ibm | daeja_viewone | 5.0.2 |
| ibm | daeja_viewone | 4.1.5.1 |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 5.0.0 |
| ibm | daeja_viewone | 4.1.5.1 |
| ibm | daeja_viewone | 5.0.1 |
IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.1.4 |
| ibm | inotes | 9.0.1.7 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | inotes | 9.0.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.0.1 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.2.2 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | inotes | 8.5.1.2 |
| ibm | inotes | 8.5.1.3 |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.5 |
IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.5.6 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.5.5 |
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2.2 |
| ibm | bigfix_platform | 9.2.0 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.1.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.2.1 |
| ibm | bigfix_platform | 9.1.3 |
| ibm | bigfix_platform | 9.1.6 |
| ibm | bigfix_platform | 9.2.4 |
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.2.5 |
| ibm | bigfix_platform | 9.1.4 |
| ibm | bigfix_platform | 9.1.5 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.3 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123860.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.5.6 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.5.5 |
IBM Tivoli Endpoint Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123903.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.5.6 |
| ibm | bigfix_platform | 9.5 |
| ibm | bigfix_platform | 9.2.7 |
| ibm | bigfix_platform | 9.2.6 |
| ibm | bigfix_platform | 9.5.5 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123904.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sensitive information about its environment which could be used in further attacks against the system. IBM X-Force ID: 123905.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-770,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.1 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123907.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable numbers. This weakness may allow attackers to expose sensitive information by guessing tokens or identifiers. IBM X-Force ID: 123909.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 123911.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_remote_control | 9.1.4 |
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 8.0.0.2 |
IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0.2 |
IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124356.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 6.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace information to an attacker. IBM X-Force ID: 124523.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124524.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rational Software Architect Design Manager 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124580.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rhapsody_design_manager | 6.0.3 |
| ibm | rhapsody_design_manager | 6.0.1 |
| ibm | rhapsody_design_manager | 6.0.2 |
| ibm | rhapsody_design_manager | 5.0.2 |
| ibm | rhapsody_design_manager | 6.0 |
| ibm | rhapsody_design_manager | 5.0 |
| ibm | rhapsody_design_manager | 5.0.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force 124630.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. IBM X-Force ID: 124631.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 6.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.1.4 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-113,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) techniques. IBM X-Force ID: 124740.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 9.5 |
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1 |
| ibm | security_guardium | 10.1.2 |
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.
CVSS 2.0
Severity: LOW
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 9.0 |
| ibm | security_guardium | 9.1 |
| ibm | security_guardium | 9.5 |
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 124747. IBM X-Force ID: 124747.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 9.0.0.0 |
| ibm | domino | 9.0.1.8 |
| ibm | domino | 9.0.1 |
| ibm | domino | 8.5.3.6 |
| ibm | domino | 8.5.3 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124750.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124752.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 124757.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tealeaf_customer_experience | 8.8 |
| ibm | tealeaf_customer_experience | 8.7 |
| ibm | tealeaf_customer_experience | 9.0.2 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124758.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124759.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124760.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.3.7 |
| ibm | content_navigator | 2.0.3.5 |
| ibm | content_navigator | 2.0.3.8 |
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 2.0.3.6 |
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-772,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 9.0.4 |
| ibm | websphere_mq | 9.0.2 |
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.2 |
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.2 |
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | * |
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rhapsody_design_manager | 6.0.3 |
| ibm | rhapsody_design_manager | 6.0.1 |
| ibm | rhapsody_design_manager | 6.0.2 |
| ibm | rhapsody_design_manager | 5.0.2 |
| ibm | rhapsody_design_manager | 6.0 |
| ibm | rhapsody_design_manager | 5.0 |
| ibm | rhapsody_design_manager | 5.0.1 |
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sdk | * |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125154.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125155.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID: 125157.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | data_server_runtime_client | - |
| ibm | db2_connect | 10.1 |
| ibm | data_server_client | - |
| ibm | db2 | 9.7 |
| ibm | data_server_driver_for_odbc_and_cli | - |
| ibm | data_server_driver_package | - |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125161.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.
CVSS 2.0
Severity: LOW
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 7.1.6.6 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 8.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 8.1.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.3.6.100 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2.8 | 2.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 8.5 |
| ibm | websphere_portal | 7.0 |
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node and utilize direct I/O to perform a read or a write to a Spectrum Scale file. This vulnerability may result in the use of an incorrect memory address, leading to a Spectrum Scale/GPFS daemon failure with a Signal 11, and possibly leading to denial of service or undetected data corruption. IBM X-Force ID: 125458.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.2 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H | 1.4 | 4.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | elastic_storage_server | 3.0.5 |
| ibm | elastic_storage_server | 2.5.5 |
| ibm | elastic_storage_server | 4.5.0 |
| ibm | elastic_storage_server | 4.6.0 |
| ibm | elastic_storage_server | 4.0.6 |
| ibm | elastic_storage_server | 2.5.0 |
| ibm | elastic_storage_server | 3.5.0 |
| ibm | elastic_storage_server | 5.0.1 |
| ibm | elastic_storage_server | 3.5.6 |
| ibm | elastic_storage_server | 2.0.0 |
| ibm | elastic_storage_server | 5.0.0 |
| ibm | elastic_storage_server | 3.0.0 |
| ibm | elastic_storage_server | 4.0.0 |
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125460.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-552,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 4.1.5.1 |
| ibm | daeja_viewone | 5.0 |
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
CVSS 2.0
Severity: LOW
Problem Type: CWE-312,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management_server | 11.5 |
| ibm | infosphere_master_data_management_server | 11.0 |
| ibm | infosphere_master_data_management_server | 11.3 |
| ibm | infosphere_master_data_management_server | 11.6 |
| ibm | infosphere_master_data_management_server | 11.4 |
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 12.10 |
IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 125719.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | insights_foundation_for_energy | 2.0 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125723.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125724.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125725.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125727.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125728.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125729.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance | 8.0.0.1 |
| ibm | mq_appliance | 8.0.0.3 |
| ibm | mq_appliance | 9.0.2 |
| ibm | mq_appliance | 8.0.0.4 |
| ibm | mq_appliance | 8.0.0.2 |
| ibm | mq_appliance | 8.0.0.5 |
| ibm | mq_appliance | 8.0.0.0 |
| ibm | mq_appliance | 9.0.1 |
| ibm | mq_appliance | 8.0.0.6 |
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.0.3 |
| ibm | tivoli_federated_identity_manager | 6.2.1.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.7 |
| ibm | tivoli_federated_identity_manager | 6.2.2.9 |
| ibm | tivoli_federated_identity_manager | 6.2.0.12 |
| ibm | tivoli_federated_identity_manager | 6.2.0.13 |
| ibm | tivoli_federated_identity_manager | 6.2.0.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.4 |
| ibm | tivoli_federated_identity_manager | 6.2.0.9 |
| ibm | tivoli_federated_identity_manager | 6.2.0.16 |
| ibm | tivoli_federated_identity_manager | 6.2.0.8 |
| ibm | tivoli_federated_identity_manager | 6.2.0.11 |
| ibm | tivoli_federated_identity_manager | 6.2.2.10 |
| ibm | tivoli_federated_identity_manager | 6.2.2.4 |
| ibm | tivoli_federated_identity_manager | 6.2.1.6 |
| ibm | tivoli_federated_identity_manager | 6.2.0.10 |
| ibm | tivoli_federated_identity_manager | 6.2.2.13 |
| ibm | tivoli_federated_identity_manager | 6.2.2.3 |
| ibm | tivoli_federated_identity_manager | 6.2.2.7 |
| ibm | tivoli_federated_identity_manager | 6.2.2.17 |
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | tivoli_federated_identity_manager | 6.2.1.5 |
| ibm | tivoli_federated_identity_manager | 6.2.2.8 |
| ibm | tivoli_federated_identity_manager | 6.2.2.15 |
| ibm | tivoli_federated_identity_manager | 6.2.0.15 |
| ibm | tivoli_federated_identity_manager | 6.2.0.17 |
| ibm | tivoli_federated_identity_manager | 6.2.2.11 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
| ibm | tivoli_federated_identity_manager | 6.2.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0.14 |
| ibm | tivoli_federated_identity_manager | 6.2.1.3 |
| ibm | tivoli_federated_identity_manager | 6.2.0.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.2.6 |
| ibm | tivoli_federated_identity_manager | 6.2.2.16 |
| ibm | tivoli_federated_identity_manager | 6.2.1.9 |
| ibm | tivoli_federated_identity_manager | 6.2.1.8 |
| ibm | tivoli_federated_identity_manager | 6.2.2.12 |
| ibm | tivoli_federated_identity_manager | 6.2.2.14 |
| ibm | tivoli_federated_identity_manager | 6.2.1.2 |
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2.8 | 2.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125976.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 8.5.2.3 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.3.2 |
| ibm | inotes | 9.0.1.3 |
| ibm | inotes | 9.0.1.6 |
| ibm | inotes | 8.5.3.4 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.1.4 |
| ibm | inotes | 9.0.1.7 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 8.5.3.3 |
| ibm | inotes | 8.5.3.5 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.2 |
| ibm | inotes | 9.0.1.4 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.0.1 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.2.2 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 9.0.1.5 |
| ibm | inotes | 8.5.1.2 |
| ibm | inotes | 8.5.1.3 |
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 9.0.1.8 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.2.4 |
IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126233.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 2.0.3.7 |
| ibm | content_navigator | 2.0.3.5 |
| ibm | content_navigator | 2.0.3.8 |
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 2.0.3.6 |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 9.0.1.8 |
| ibm | inotes | 9.0.0.0 |
| ibm | inotes | 9.0.1.0 |
| ibm | inotes | 8.5.2.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.0.0 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.1.0 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.3.0 |
| ibm | inotes | 8.5.2.4 |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.1.0.0 |
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 7.2.0.1 |
| ibm | openpages_grc_platform | 7.1.0.2 |
| ibm | openpages_grc_platform | 7.2.0.2 |
| ibm | openpages_grc_platform | 7.1.0.1 |
| ibm | openpages_grc_platform | 7.2.0.3 |
| ibm | openpages_grc_platform | 7.3.0.0 |
| ibm | openpages_grc_platform | 7.2.0.4 |
| ibm | openpages_grc_platform | 7.1.0.3 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126242.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126243.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 4.2.0 |
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.2 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126246.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_requirements_composer | 4.0.4 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 4.0.2 |
| ibm | rational_requirements_composer | 4.0.1 |
| ibm | rational_requirements_composer | 4.0.3 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.5 |
| ibm | rational_requirements_composer | 4.0.6 |
| ibm | rational_requirements_composer | 5.0.0 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.
CVSS 2.0
Severity: LOW
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.7.100 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 7.1.7.200 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 8.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.7 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 8.1.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.3.6.100 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 8.1.1 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.4 |
IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.2 |
IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that could e used to conduct further attacks. IBM X-Force ID: 126457.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | insights_foundation_for_energy | 2.0 |
IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126460.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | insights_foundation_for_energy | 2.0 |
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126462.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126524.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 11.7 |
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5 |
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.3.4 |
| ibm | atlas_ediscovery_process_management | 6.0.3.2 |
| ibm | atlas_ediscovery_process_management | 6.0.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.5 |
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126681.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.3.4 |
| ibm | atlas_ediscovery_process_management | 6.0.3.2 |
| ibm | atlas_ediscovery_process_management | 6.0.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.5 |
IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.3.4 |
| ibm | atlas_ediscovery_process_management | 6.0.3.2 |
| ibm | atlas_ediscovery_process_management | 6.0.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.5 |
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | atlas_ediscovery_process_management | 6.0.3.4 |
| ibm | atlas_ediscovery_process_management | 6.0.3.2 |
| ibm | atlas_ediscovery_process_management | 6.0.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.3 |
| ibm | atlas_ediscovery_process_management | 6.0.3.5 |
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management_essentials | 7.5.0.7 |
| ibm | maximo_asset_management | 7.5.0.2 |
| ibm | maximo_asset_management_essentials | 7.6.0.6 |
| ibm | maximo_asset_management | 7.6.0.3 |
| ibm | maximo_asset_management_essentials | 7.6.0.7 |
| ibm | maximo_asset_management | 7.5.0.1 |
| ibm | maximo_asset_management | 7.5.0.10 |
| ibm | maximo_asset_management_essentials | 7.6.0.3 |
| ibm | maximo_asset_management_essentials | 7.5.0.5 |
| ibm | maximo_asset_management | 7.6.0.4 |
| ibm | maximo_asset_management_essentials | 7.6.0.0 |
| ibm | maximo_asset_management_essentials | 7.6.0.4 |
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.6 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management_essentials | 7.5.0.8 |
| ibm | maximo_asset_management_essentials | 7.6.0.2 |
| ibm | maximo_asset_management | 7.6.0.5 |
| ibm | maximo_asset_management | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.2 |
| ibm | maximo_asset_management_essentials | 7.5.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.9 |
| ibm | maximo_asset_management_essentials | 7.5.0.10 |
| ibm | maximo_asset_management | 7.5.0.6 |
| ibm | maximo_asset_management | 7.5.0.0 |
| ibm | maximo_asset_management | 7.6.0.7 |
| ibm | maximo_asset_management | 7.5.0.7 |
| ibm | maximo_asset_management_essentials | 7.5.0.9 |
| ibm | maximo_asset_management | 7.5.0.4 |
| ibm | maximo_asset_management | 7.5.0.5 |
| ibm | maximo_asset_management_essentials | 7.6.0.1 |
| ibm | maximo_asset_management_essentials | 7.5.0.3 |
| ibm | maximo_asset_management | 7.6.0.1 |
| ibm | maximo_asset_management_essentials | 7.6.0.5 |
| ibm | maximo_asset_management | 7.5.0.8 |
| ibm | maximo_asset_management | 7.6.0.6 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126686.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0 |
| ibm | security_identity_manager | 7.0 |
IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126856.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126857.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 126861.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126862.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-209,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
| ibm | jazz_reporting_service | 6.0.4 |
Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they do not have access to. IBM X-Force ID: 126864.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.2.1 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.5.2.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.2.1 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.5.2.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.2.1 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.5.2.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126867.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.2.1 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.5.2.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000_software | 1.5 |
| ibm | storwize_unified_v7000_software | 1.6 |
A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-829,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operations_analytics_predictive_insights | 1.3.3 |
| ibm | operations_analytics_predictive_insights | 1.3.0 |
| ibm | operations_analytics_predictive_insights | 1.3.6 |
| ibm | operations_analytics_predictive_insights | 1.3.2 |
| ibm | operations_analytics_predictive_insights | 1.3.5 |
| ibm | operations_analytics_predictive_insights | 1.3.1 |
IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | runbook_automation | - |
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | 7.1.3.1 |
| ibm | tivoli_storage_manager | 6.3.2.2 |
| ibm | tivoli_storage_manager | 6.3.6 |
| ibm | tivoli_storage_manager | 6.3.3 |
| ibm | tivoli_storage_manager | 6.1.1 |
| ibm | tivoli_storage_manager | 7.1.3 |
| ibm | tivoli_storage_manager | 7.1.6.5 |
| ibm | tivoli_storage_manager | 6.1.5 |
| ibm | tivoli_storage_manager | 6.2.4 |
| ibm | tivoli_storage_manager | 7.1..5.100 |
| ibm | tivoli_storage_manager | 7.1.3.2 |
| ibm | tivoli_storage_manager | 6.2.3 |
| ibm | tivoli_storage_manager | 7.1.0.3 |
| ibm | tivoli_storage_manager | 7.1.4.2 |
| ibm | tivoli_storage_manager | 7.1.4 |
| ibm | tivoli_storage_manager | 7.1.6 |
| ibm | tivoli_storage_manager | 7.1.1.1 |
| ibm | tivoli_storage_manager | 6.4.3 |
| ibm | tivoli_storage_manager | 7.1.1.100 |
| ibm | tivoli_storage_manager | 7.1.1 |
| ibm | tivoli_storage_manager | 6.4.2.600 |
| ibm | tivoli_storage_manager | 6.3.1.2 |
| ibm | tivoli_storage_manager | 6.3.0.15 |
| ibm | tivoli_storage_manager | 6.4.1 |
| ibm | tivoli_storage_manager | 6.4.2 |
| ibm | tivoli_storage_manager | 6.1.3 |
| ibm | tivoli_storage_manager | 7.1.1.300 |
| ibm | tivoli_storage_manager | 7.1.5.200 |
| ibm | tivoli_storage_manager | 7.1.3.000 |
| ibm | tivoli_storage_manager | 6.1 |
| ibm | tivoli_storage_manager | 6.2.1 |
| ibm | tivoli_storage_manager | 6.1.0 |
| ibm | tivoli_storage_manager | 6.3 |
| ibm | tivoli_storage_manager | 6.4.2.200 |
| ibm | tivoli_storage_manager | 6.4.2.500 |
| ibm | tivoli_storage_manager | 7.1.1.2 |
| ibm | tivoli_storage_manager | 6.3.1 |
| ibm | tivoli_storage_manager | 6.1.5.5 |
| ibm | tivoli_storage_manager | 6.1.2 |
| ibm | tivoli_storage_manager | 7.1.4.1 |
| ibm | tivoli_storage_manager | 7.1 |
| ibm | tivoli_storage_manager | 7.1.5 |
| ibm | tivoli_storage_manager | 6.3.4 |
| ibm | tivoli_storage_manager | 7.1.0.1 |
| ibm | tivoli_storage_manager | 7.1.3.100 |
| ibm | tivoli_storage_manager | 6.4.3.1 |
| ibm | tivoli_storage_manager | 6.3.5 |
| ibm | tivoli_storage_manager | 6.3.0.17 |
| ibm | tivoli_storage_manager | 6.1.5.6 |
| ibm | tivoli_storage_manager | 8.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.1.0 |
| ibm | tivoli_storage_manager | 7.1.1.200 |
| ibm | tivoli_storage_manager | 8.1.0 |
| ibm | tivoli_storage_manager | 6.2.0 |
| ibm | tivoli_storage_manager | 6.3.0.5 |
| ibm | tivoli_storage_manager | 6.3.6.100 |
| ibm | tivoli_storage_manager | 7.1.0.2 |
| ibm | tivoli_storage_manager | 6.4.2.100 |
| ibm | tivoli_storage_manager | 6.3.5.1 |
| ibm | tivoli_storage_manager | 6.1.4 |
| ibm | tivoli_storage_manager | 6.2.2 |
| ibm | tivoli_storage_manager | 6.1.5.4 |
IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_connect | 5.0.7.1 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
CVSS 2.0
Severity: LOW
Problem Type: CWE-276,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_management | 4.0.0.1 |
| ibm | api_management | 4.0.1.0 |
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_management | 4.0.2.0 |
| ibm | api_management | 4.0.4.0 |
| ibm | api_management | 4.0.4.4 |
| ibm | api_management | 4.0.3.0 |
| ibm | api_management | 4.0.4.2 |
| ibm | api_management | 4.0.4.1 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_management | 4.0.4.3 |
| ibm | api_management | 4.0.2.1 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
| ibm | api_management | 4.0.4.5 |
| ibm | api_management | 4.0.0.0 |
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 127385.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 6.0.0.6 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.1.12 |
| ibm | websphere_commerce | 8.0.1.2 |
| ibm | websphere_commerce | 8.0.0.15 |
| ibm | websphere_commerce | 8.0.0.13 |
| ibm | websphere_commerce | 8.0.0.10 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 6.0.0.5 |
| ibm | websphere_commerce | 8.0.1.8 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 6.0.0.1 |
| ibm | websphere_commerce | 6.0.0.2 |
| ibm | websphere_commerce | 8.0.1.4 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.0.19 |
| ibm | websphere_commerce | 8.0.1.5 |
| ibm | websphere_commerce | 8.0.1.9 |
| ibm | websphere_commerce | 6.0.0.3 |
| ibm | websphere_commerce | 8.0.0.14 |
| ibm | websphere_commerce | 8.0.1.7 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 6.0.0.11 |
| ibm | websphere_commerce | 6.0.0.10 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.1.1 |
| ibm | websphere_commerce | 6.0.0.7 |
| ibm | websphere_commerce | 6.0.0.8 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 6.0.0.0 |
| ibm | websphere_commerce | 8.0.1.0 |
| ibm | websphere_commerce | 7.0.0.8 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | 8.0.1.11 |
| ibm | websphere_commerce | 8.0.0.16 |
| ibm | websphere_commerce | 8.0.0.11 |
| ibm | websphere_commerce | 8.0.1.6 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 6.0.0.4 |
| ibm | websphere_commerce | 6.0.0.9 |
| ibm | websphere_commerce | 8.0.1.3 |
| ibm | websphere_commerce | 8.0.0.12 |
| ibm | websphere_commerce | 8.0.0.18 |
| ibm | websphere_commerce | 8.0.0.17 |
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-345,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0 |
| ibm | security_identity_manager | 7.0.1 |
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.0.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_governance_and_intelligence | 5.2.0 |
| ibm | security_privileged_identity_manager | 2.0.0 |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 127396.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.
CVSS 2.0
Severity: LOW
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | * |
| ibm | integration_bus | * |
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | inotes | 8.5.2.1 |
| ibm | inotes | 9.0.1.1 |
| ibm | inotes | 9.0.1.8 |
| ibm | inotes | 9.0 |
| ibm | inotes | 8.5.3.6 |
| ibm | inotes | 8.5.1.1 |
| ibm | inotes | 8.5.1.5 |
| ibm | inotes | 8.5.3 |
| ibm | inotes | 9.0.1 |
| ibm | inotes | 8.5.3.1 |
| ibm | inotes | 8.5.1 |
| ibm | inotes | 8.5.2.4 |
| ibm | inotes | 8.5 |
| ibm | inotes | 8.5.2 |
IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maas360_dtm | * |
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.7.0 |
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.7.0 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127579.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5 |
| ibm | cognos_analytics | 11.0.6 |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5 |
| ibm | cognos_analytics | 11.0.6 |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127587.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 6.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127632.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_streams | 4.1 |
| ibm | infosphere_streams | 4.0 |
| ibm | infosphere_streams | 4.0.1 |
| ibm | infosphere_streams | 4.2.1 |
| ibm | infosphere_streams | 4.1.1 |
| ibm | infosphere_streams | 4.2 |
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 7.5.0.7 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.5.0.5 |
| ibm | websphere_mq | 7.5.0.8 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 7.5.0.6 |
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 11.1.0.0 |
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 128105.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_services_procurement | 10.0.0.4 |
| ibm | emptoris_services_procurement | 10.0.0.3 |
| ibm | emptoris_services_procurement | 10.0.0.1 |
| ibm | emptoris_services_procurement | 10.0.0.2 |
| ibm | emptoris_services_procurement | 10.0.0.5 |
| ibm | emptoris_services_procurement | 10.1.1.0 |
| ibm | emptoris_services_procurement | 10.0.0.0 |
IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_services_procurement | 10.0.0.4 |
| ibm | emptoris_services_procurement | 10.0.0.3 |
| ibm | emptoris_services_procurement | 10.0.0.1 |
| ibm | emptoris_services_procurement | 10.0.0.2 |
| ibm | emptoris_services_procurement | 10.0.0.5 |
| ibm | emptoris_services_procurement | 10.1.1.0 |
| ibm | emptoris_services_procurement | 10.0.0.0 |
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 128107.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_services_procurement | 10.0.0.4 |
| ibm | emptoris_services_procurement | 10.0.0.3 |
| ibm | emptoris_services_procurement | 10.0.0.1 |
| ibm | emptoris_services_procurement | 10.0.0.2 |
| ibm | emptoris_services_procurement | 10.0.0.5 |
| ibm | emptoris_services_procurement | 10.1.1.0 |
| ibm | emptoris_services_procurement | 10.0.0.0 |
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128109.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_services_procurement | 10.0.0.4 |
| ibm | emptoris_services_procurement | 10.0.0.3 |
| ibm | emptoris_services_procurement | 10.0.0.1 |
| ibm | emptoris_services_procurement | 10.0.0.2 |
| ibm | emptoris_services_procurement | 10.0.0.5 |
| ibm | emptoris_services_procurement | 10.1.1.0 |
| ibm | emptoris_services_procurement | 10.0.0.0 |
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128110.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.1.0 |
| ibm | emptoris_sourcing | 9.5.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.1.3 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128170.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_spend_analysis | 10.0.2 |
| ibm | emptoris_spend_analysis | 10.0.0.0 |
| ibm | emptoris_spend_analysis | 10.1.1 |
| ibm | emptoris_spend_analysis | 9.5.0.4 |
| ibm | emptoris_spend_analysis | 10.0.4 |
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.0.1 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 10.0.0.1 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128171.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_spend_analysis | 9.5.0.4 |
| ibm | emptoris_spend_analysis | 9.5.0.0 |
| ibm | emptoris_spend_analysis | 10.0.2.0 |
| ibm | emptoris_spend_analysis | 10.0.1.0 |
| ibm | emptoris_spend_analysis | 10.1.1.0 |
| ibm | emptoris_spend_analysis | 9.5.0.3 |
| ibm | emptoris_spend_analysis | 9.5.0.2 |
| ibm | emptoris_spend_analysis | 10.0.0.0 |
| ibm | emptoris_spend_analysis | 10.0.0.1 |
| ibm | emptoris_spend_analysis | 10.0.4.0 |
| ibm | emptoris_spend_analysis | 9.5.0.1 |
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.1.0 |
| ibm | emptoris_sourcing | 9.5.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.1.3 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128173.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_strategic_supply_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.1 |
| ibm | emptoris_strategic_supply_management | 10.1.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.9 |
| ibm | emptoris_strategic_supply_management | 10.1.1.9 |
| ibm | emptoris_strategic_supply_management | 10.0.2.4 |
| ibm | emptoris_strategic_supply_management | 10.1.0.3 |
| ibm | emptoris_strategic_supply_management | 10.1.1.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.0 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.1.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.0.1.4 |
| ibm | emptoris_strategic_supply_management | 10.1.1.6 |
| ibm | emptoris_strategic_supply_management | 10.1.1.7 |
| ibm | emptoris_strategic_supply_management | 10.0.2.11 |
| ibm | emptoris_strategic_supply_management | 10.0.2.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.13 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.3 |
| ibm | emptoris_strategic_supply_management | 10.0.2.14 |
| ibm | emptoris_strategic_supply_management | 10.0.2.15 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.9 |
| ibm | emptoris_strategic_supply_management | 10.0.0.2 |
| ibm | emptoris_strategic_supply_management | 10.0.4.0 |
| ibm | emptoris_strategic_supply_management | 10.1.0.4 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.10 |
| ibm | emptoris_strategic_supply_management | 10.0.2.17 |
| ibm | emptoris_strategic_supply_management | 10.1.1.2 |
| ibm | emptoris_strategic_supply_management | 10.0.2.10 |
| ibm | emptoris_strategic_supply_management | 10.1.0.6 |
| ibm | emptoris_strategic_supply_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.16 |
| ibm | emptoris_strategic_supply_management | 10.1.1.10 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.1 |
| ibm | emptoris_strategic_supply_management | 10.0.2.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.2 |
| ibm | emptoris_strategic_supply_management | 10.1.0.8 |
| ibm | emptoris_strategic_supply_management | 10.1.1.5 |
| ibm | emptoris_strategic_supply_management | 10.0.1.3 |
| ibm | emptoris_strategic_supply_management | 10.1.0.2 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.3 |
| ibm | emptoris_strategic_supply_management | 10.0.0.3 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.0.0.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.1.1 |
| ibm | emptoris_strategic_supply_management | 10.1.0.5 |
| ibm | emptoris_strategic_supply_management | 10.1.0.11 |
| ibm | emptoris_strategic_supply_management | 10.0.1.0 |
| ibm | emptoris_strategic_supply_management | 10.1.1.8 |
| ibm | emptoris_strategic_supply_management | 10.0.2.1 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.7 |
| ibm | emptoris_strategic_supply_management | 10.1.0.0 |
| ibm | emptoris_strategic_supply_management | 10.0.2.12 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.6 |
| ibm | emptoris_supplier_lifecycle_management | 10.0.2.5 |
| ibm | emptoris_strategic_supply_management | 10.1.1.4 |
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128174.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.1.0 |
| ibm | emptoris_sourcing | 9.5.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.1.3 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128177.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | emptoris_sourcing | 10.0.1 |
| ibm | emptoris_sourcing | 9.5.1.1 |
| ibm | emptoris_sourcing | 10.0.2 |
| ibm | emptoris_sourcing | 9.5 |
| ibm | emptoris_sourcing | 10.0.0 |
| ibm | emptoris_sourcing | 9.5.1.0 |
| ibm | emptoris_sourcing | 9.5.0.2 |
| ibm | emptoris_sourcing | 9.5.1.2 |
| ibm | emptoris_sourcing | 10.0.4 |
| ibm | emptoris_sourcing | 10.1.0 |
| ibm | emptoris_sourcing | 10.1.1 |
| ibm | emptoris_sourcing | 9.5.1.3 |
| ibm | emptoris_sourcing | 10.1.3 |
| ibm | emptoris_sourcing | 9.5.0.1 |
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.3.0 |
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128376.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_network_security | 5.4 |
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_network_security | 5.4 |
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 128378.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager_for_web_8.0_firmware | * |
| ibm | security_access_manager_9.0_firmware | * |
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i | 7.1 |
| ibm | i | 7.2 |
| ibm | i | 6.1 |
| ibm | i | 7.3 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128461.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tririga_application_platform | 3.5.2.3 |
| ibm | tririga_application_platform | 3.5.1.3 |
| ibm | tririga_application_platform | 3.4.1.2 |
| ibm | tririga_application_platform | 3.4.2.4 |
| ibm | tririga_application_platform | 3.4.2.0 |
| ibm | tririga_application_platform | 3.3.2.5 |
| ibm | tririga_application_platform | 3.5.2.1 |
| ibm | tririga_application_platform | 3.5.1 |
| ibm | tririga_application_platform | 3.3.0.1 |
| ibm | tririga_application_platform | 3.5.3 |
| ibm | tririga_application_platform | 3.5.0.2 |
| ibm | tririga_application_platform | 3.3.1.0 |
| ibm | tririga_application_platform | 3.3.2.1 |
| ibm | tririga_application_platform | 3.3.0.2 |
| ibm | tririga_application_platform | 3.3.2.0 |
| ibm | tririga_application_platform | 3.3.2.2 |
| ibm | tririga_application_platform | 3.4.2.2 |
| ibm | tririga_application_platform | 3.3.1.1 |
| ibm | tririga_application_platform | 3.5.0.0 |
| ibm | tririga_application_platform | 3.4.2.1 |
| ibm | tririga_application_platform | 3.4.2.3 |
| ibm | tririga_application_platform | 3.5.2 |
| ibm | tririga_application_platform | 3.5.0.1 |
| ibm | tririga_application_platform | 3.4.1.0 |
| ibm | tririga_application_platform | 3.4.0.1 |
| ibm | tririga_application_platform | 3.3.2.4 |
| ibm | tririga_application_platform | 3.4.1.1 |
| ibm | tririga_application_platform | 3.3.1.2 |
| ibm | tririga_application_platform | 3.5.1.1 |
| ibm | tririga_application_platform | 3.4.2.5 |
| ibm | tririga_application_platform | 3.4.0.0 |
| ibm | tririga_application_platform | 3.3.1.3 |
| ibm | tririga_application_platform | 3.5.1.2 |
| ibm | tririga_application_platform | 3.5.2.2 |
| ibm | tririga_application_platform | 3.3.2.3 |
| ibm | tririga_application_platform | 3.4.1.3 |
| ibm | tririga_application_platform | 3.3.0.0 |
A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.6 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | security_access_manager_firmware | 9.0.2.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.4 |
| ibm | security_access_manager_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.2 |
| ibm | security_access_manager_firmware | 9.0.2.1 |
| ibm | security_access_manager_firmware | 9.0.3.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
| ibm | security_access_manager_firmware | 9.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile | 8.0.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.5 |
| ibm | security_access_manager_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.4 |
| ibm | security_access_manager_for_web_firmware | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.6 |
| ibm | security_access_manager_for_mobile | 8.0.1.5 |
| ibm | security_access_manager_firmware | 9.0.1.0 |
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager | * |
| ibm | security_access_manager_for_web | * |
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager | * |
| ibm | security_access_manager_for_web | * |
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128612.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.3.0 |
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | 9.0.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.0.1 |
| ibm | security_access_manager_9.0_firmware | 9.0.3 |
| ibm | security_access_manager_9.0_firmware | 9.0.2.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.1.0 |
| ibm | security_access_manager_9.0_firmware | 9.0.3.1 |
| ibm | security_access_manager_9.0_firmware | 9.0.2.1 |
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | * |
| ibm | security_access_manager | * |
| ibm | security_access_manager_for_web | * |
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2 |
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_manager | 7.0.0.0 |
| ibm | security_privileged_identity_manager | 2.0.2 |
| ibm | security_privileged_identity_manager | 2.0.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_privileged_identity_manager | 2.0 |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 8.0.4.6 |
| ibm | websphere_commerce | 8.0.4.0 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.1.12 |
| ibm | websphere_commerce | 8.0.4.7 |
| ibm | websphere_commerce | 8.0.1.2 |
| ibm | websphere_commerce | 8.0.3.3 |
| ibm | websphere_commerce | 8.0.0.15 |
| ibm | websphere_commerce | 8.0.0.13 |
| ibm | websphere_commerce | 8.0.0.10 |
| ibm | websphere_commerce | 8.0.1.8 |
| ibm | websphere_commerce | 8.0.4.3 |
| ibm | websphere_commerce | 8.0.3.1 |
| ibm | websphere_commerce | 8.0.1.4 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.0.19 |
| ibm | websphere_commerce | 8.0.3.4 |
| ibm | websphere_commerce | 8.0.1.5 |
| ibm | websphere_commerce | 8.0.1.9 |
| ibm | websphere_commerce | 8.0.4.2 |
| ibm | websphere_commerce | 8.0.0.14 |
| ibm | websphere_commerce | 8.0.4.1 |
| ibm | websphere_commerce | 8.0.4.8 |
| ibm | websphere_commerce | 8.0.1.7 |
| ibm | websphere_commerce | 8.0.4.4 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.1.1 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 8.0.1.10 |
| ibm | websphere_commerce | 8.0.3.2 |
| ibm | websphere_commerce | 8.0.1.0 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 8.0.4.5 |
| ibm | websphere_commerce | 8.0.1.11 |
| ibm | websphere_commerce | 8.0.3.0 |
| ibm | websphere_commerce | 8.0.0.16 |
| ibm | websphere_commerce | 8.0.0.11 |
| ibm | websphere_commerce | 8.0.1.13 |
| ibm | websphere_commerce | 8.0.1.6 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 8.0.1.3 |
| ibm | websphere_commerce | 8.0.0.12 |
| ibm | websphere_commerce | 8.0.0.18 |
| ibm | websphere_commerce | 8.0.0.17 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5 |
| ibm | cognos_analytics | 11.0.6 |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128624.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_access_manager_for_e-business | 6.1.1.23 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.9 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.2 |
| ibm | security_access_manager_for_web_software | 7.0.0.6 |
| ibm | security_access_manager_for_web | 8.0.0.2 |
| ibm | security_access_manager_for_web | 8.0.1.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.16 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.12 |
| ibm | security_access_manager_for_web_software | 7.0.0.13 |
| ibm | security_access_manager_for_web | 8.0.0.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.4 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.30 |
| ibm | security_access_manager_for_web | 8.0.0.5 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.20 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.18 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.6 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.6 |
| ibm | security_access_manager_for_web_software | 7.0.0.3 |
| ibm | security_access_manager_for_mobile | 8.0.0.31 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.4 |
| ibm | security_access_manager_for_mobile | 8.0 |
| ibm | security_access_manager | 9.0.0.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.21 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.23 |
| ibm | security_access_manager_for_mobile | 8.0.0.0 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.29 |
| ibm | security_access_manager_for_web_software | 7.0.0.11 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.5 |
| ibm | security_access_manager_for_web_software | 7.0.0.7 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.14 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.28 |
| ibm | security_access_manager_for_web_software | 7.0.0.18 |
| ibm | security_access_manager_for_web_software | 7.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.29 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.28 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.25 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.31 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.29 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.16 |
| ibm | security_access_manager_for_mobile | 8.0.1.6 |
| ibm | security_access_manager_for_mobile | 8.0.1.5 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.6 |
| ibm | security_access_manager_for_web_software | 7.0.0.14 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.30 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.7 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.20 |
| ibm | security_access_manager_for_web_software | 7.0.0.15 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.17 |
| ibm | security_access_manager_for_web | 8.0.0.31 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.14 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.18 |
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.25 |
| ibm | security_access_manager_for_web_software | 7.0.0.25 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.16 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.19 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.3 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.30 |
| ibm | security_access_manager_for_web_software | 7.0.0.20 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.27 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.7 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0 |
| ibm | security_access_manager_for_web | 8.0.1.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.8 |
| ibm | security_access_manager_for_web | 8.0.1.6 |
| ibm | security_access_manager | 9.0.1.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.13 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.22 |
| ibm | security_access_manager_for_web_appliance | 7.0 |
| ibm | security_access_manager | 9.0.2.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.21 |
| ibm | security_access_manager_for_mobile | 8.0.0.22 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.13 |
| ibm | security_access_manager_for_web_software | 7.0.0.28 |
| ibm | security_access_manager_for_mobile | 8.0.1.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.2 |
| ibm | security_access_manager_for_web_software | 7.0.0.1 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.8 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.20 |
| ibm | security_access_manager_for_web_software | 7.0.0.2 |
| ibm | security_access_manager_for_web | 8.0.0.1 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.7 |
| ibm | security_access_manager_for_web | 8.0.1.4 |
| ibm | security_access_manager_for_web | 8.0.0.4 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.25 |
| ibm | security_access_manager_for_web_software | 7.0.0.21 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.22 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.11 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.10 |
| ibm | security_access_manager_for_web_software | 7.0.0.23 |
| ibm | security_access_manager_for_web_software | 7.0.0.26 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.19 |
| ibm | security_access_manager_for_web_software | 7.0.0.24 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.5 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.23 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.2 |
| ibm | security_access_manager_for_web_software | 7.0.0.12 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.11 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.10 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.9 |
| ibm | security_access_manager_for_web_software | 7.0.0.10 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.9 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.13 |
| ibm | security_access_manager_for_web_software | 7.0.0.22 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.21 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.24 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.15 |
| ibm | security_access_manager_for_web_software | 7.0.0.27 |
| ibm | security_access_manager_for_web_software | 7.0.0.17 |
| ibm | security_access_manager_for_web_software | 7.0.0.9 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.27 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.12 |
| ibm | security_access_manager_for_web_software | 7.0.0.16 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.24 |
| ibm | security_access_manager_for_web | 8.0.1.3 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.15 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.11 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.18 |
| ibm | security_access_manager | 9.0.0.0 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.28 |
| ibm | security_access_manager_for_web | 8.0.1.5 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.8 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.17 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.26 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.17 |
| ibm | security_access_manager_for_web | 8.0.0.22 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.5 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
| ibm | security_access_manager_for_web | 8.0.1.2 |
| ibm | security_access_manager_for_mobile | 8.0.1.1 |
| ibm | security_access_manager_for_web_software | 7.0.0.8 |
| ibm | security_access_manager_for_web_software | 7.0.0.29 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.19 |
| ibm | security_access_manager_for_mobile | 8.0.0.4 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.4 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.26 |
| ibm | security_access_manager | 9.0.2.0 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.15 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.3 |
| ibm | tivoli_access_manager_for_e-business | 6.1.1.24 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.22 |
| ibm | security_access_manager_for_web_software | 7.0.0.19 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.26 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.3 |
| ibm | security_access_manager_for_web_software | 7.0.0.4 |
| ibm | security_access_manager_for_web | 8.0.0.3 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.14 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.1 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.1 |
| ibm | security_access_manager_for_web_software | 7.0.0.5 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.2 |
| ibm | security_access_manager_for_web | 8.0 |
| ibm | security_access_manager | 9.0.3.0 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.12 |
| ibm | tivoli_access_manager_for_e-business | 6.1.0.10 |
| ibm | security_access_manager_for_web_software | 7.0.0.30 |
| ibm | security_access_manager_for_web_appliance | 7.0.0.27 |
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 6.0.4 |
IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_network_security | 5.4 |
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | 6.1.0.3 |
| ibm | urbancode_deploy | 6.2.6.1 |
| ibm | urbancode_deploy | 6.2.3.1 |
| ibm | urbancode_deploy | 6.1.1.8 |
| ibm | urbancode_deploy | 6.2.5.0 |
| ibm | urbancode_deploy | 6.1.1.1 |
| ibm | urbancode_deploy | 6.1.1.2 |
| ibm | urbancode_deploy | 6.1.3.3 |
| ibm | urbancode_deploy | 6.2.4.1 |
| ibm | urbancode_deploy | 6.2.5.1 |
| ibm | urbancode_deploy | 6.1.1.5 |
| ibm | urbancode_deploy | 6.2.1.0 |
| ibm | urbancode_deploy | 6.2.4.2 |
| ibm | urbancode_deploy | 6.1.3.4 |
| ibm | urbancode_deploy | 6.1.0.1 |
| ibm | urbancode_deploy | 6.2.0.0 |
| ibm | urbancode_deploy | 6.1.1.6 |
| ibm | urbancode_deploy | 6.1.0.4 |
| ibm | urbancode_deploy | 6.1.1.0 |
| ibm | urbancode_deploy | 6.1.3.1 |
| ibm | urbancode_deploy | 6.2.0.1 |
| ibm | urbancode_deploy | 6.1.3.2 |
| ibm | urbancode_deploy | 6.1.3.6 |
| ibm | urbancode_deploy | 6.2.1.1 |
| ibm | urbancode_deploy | 6.1 |
| ibm | urbancode_deploy | 6.1.3.5 |
| ibm | urbancode_deploy | 6.1.2 |
| ibm | urbancode_deploy | 6.2.0.2 |
| ibm | urbancode_deploy | 6.2.1.2 |
| ibm | urbancode_deploy | 6.1.3 |
| ibm | urbancode_deploy | 6.1.1.3 |
| ibm | urbancode_deploy | 6.2.4.0 |
| ibm | urbancode_deploy | 6.2.2.0 |
| ibm | urbancode_deploy | 6.1.1.7 |
| ibm | urbancode_deploy | 6.2.5.2 |
| ibm | urbancode_deploy | 6.1.1.4 |
| ibm | urbancode_deploy | 6.2.2.1 |
| ibm | urbancode_deploy | 6.2.3.0 |
| ibm | urbancode_deploy | 6.2.6.0 |
| ibm | urbancode_deploy | 6.2.0.201 |
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.7.0 |
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | 5.2.6 |
| ibm | sterling_b2b_integrator | 5.2 |
| ibm | sterling_b2b_integrator | 5.2.1 |
| ibm | sterling_b2b_integrator | 5.2.5 |
| ibm | sterling_b2b_integrator | 5.2.3 |
| ibm | sterling_b2b_integrator | 5.2.4 |
| ibm | sterling_b2b_integrator | 5.2.2 |
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129020.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.5.0.0 |
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter is "scope"; if you set as its value a "realm" not defined in authenticationConfig.xml, you get an HTTP 403 Forbidden response and the value will be reflected in the body of the HTTP response. By setting it to arbitrary JavaScript code it is possible to modify the flow of the authorization function, potentially leading to credential disclosure within a trusted session.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mobilefirst_platform_foundation | 8.0.0.0 |
| ibm | worklight | 6.1.0.2 |
| ibm | worklight | 6.2.0.1 |
| ibm | mobilefirst_platform_foundation | 6.3.0.0 |
| ibm | mobilefirst_platform_foundation | 7.0.0.0 |
| ibm | mobilefirst_platform_foundation | 7.1.0.0 |
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0.0.2 |
| ibm | websphere_application_server | 8.0.0.8 |
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 8.0.0.5 |
| ibm | websphere_application_server | 9.0.0.4 |
| ibm | websphere_application_server | 8.0.0.3 |
| ibm | websphere_application_server | 8.0.0.6 |
| ibm | websphere_application_server | 8.0.0.1 |
| ibm | websphere_application_server | 8.0.0.4 |
| ibm | websphere_application_server | 8.0.0.7 |
| ibm | websphere_application_server | 8.0.0.0 |
| ibm | websphere_application_server | 8.0.0.12 |
| ibm | websphere_application_server | 9.0.0.3 |
| ibm | websphere_application_server | 8.0.0.9 |
| ibm | websphere_application_server | 8.0.0.11 |
| ibm | websphere_application_server | 8.5.5.11 |
| ibm | websphere_application_server | 8.0.0.10 |
| ibm | websphere_application_server | 8.5.5.10 |
| ibm | websphere_application_server | 8.0.0.13 |
| ibm | websphere_application_server | 9.0.0.1 |
| ibm | websphere_application_server | 8.0.0.2 |
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129577.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.1 |
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 2.0.3 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 129578.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0.0.4 |
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129617.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_tm1 | 10.2.2 |
| ibm | cognos_tm1 | 10.2 |
IBM Jazz Foundation Products could disclose sensitive information during a scan that could lead to further attacks against the system. IBM X-Force ID: 129619.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 6.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | informix_dynamic_server | 12.10 |
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 129826.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2 | 10.5.0.4 |
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2_connect | 10.1 |
| ibm | db2_connect | 9.7.0.11 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2_connect | 10.1.0.3 |
| ibm | db2_connect | 9.7.0.8 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2_connect | 9.7.0.6 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2_connect | 10.5.0.5 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2_connect | 9.7 |
| ibm | db2_connect | 11.1.0.0 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2_connect | 10.1.0.5 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2_connect | 10.1.0.4 |
| ibm | db2 | 9.7 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2_connect | 9.7.0.4 |
| ibm | db2_connect | 10.1.0.2 |
| ibm | db2_connect | 10.5.0.3 |
| ibm | db2_connect | 9.7.0.9 |
| ibm | db2 | 10.5 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2_connect | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.2 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2_connect | 10.5.0.4 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.1 |
| ibm | db2_connect | 9.7.0.10 |
| ibm | db2_connect | 10.1.0.1 |
| ibm | db2_connect | 10.5.0.6 |
| ibm | db2_connect | 9.7.0.7 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2_connect | 9.7.0.3 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2_connect | 10.5.0.7 |
| ibm | db2_connect | 10.5.0.1 |
| ibm | db2 | 10.5.0.6 |
| ibm | db2_connect | 10.5 |
| ibm | db2_connect | 9.7.0.1 |
| ibm | db2_connect | 9.7.0.2 |
IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129831.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | 9.2 |
| ibm | bigfix_platform | 9.5 |
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129832.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.1 |
| ibm | content_navigator | 2.0.3.8 |
| ibm | content_navigator | 3.0.0 |
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.5 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130411.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_9.0_firmware | * |
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 130676.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_mobile | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.6 |
| ibm | security_access_manager_for_mobile | 8.0.1.4 |
| ibm | security_access_manager_firmware | 9.0.2.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.4 |
| ibm | security_access_manager_firmware | 9.0.0 |
| ibm | security_access_manager_for_mobile | 8.0.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.2 |
| ibm | security_access_manager_firmware | 9.0.2.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.2 |
| ibm | security_access_manager_for_web_firmware | 8.0.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.5 |
| ibm | security_access_manager_for_mobile | 8.0.0.5 |
| ibm | security_access_manager_firmware | 9.0.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.4 |
| ibm | security_access_manager_for_mobile | 8.0.0 |
| ibm | security_access_manager_for_web_firmware | 8.0.1.5 |
| ibm | security_access_manager_firmware | 9.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.4 |
| ibm | security_access_manager_for_web_firmware | 8.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.3 |
| ibm | security_access_manager_for_web_firmware | 8.0.0.1 |
| ibm | security_access_manager_for_mobile | 8.0.1.6 |
| ibm | security_access_manager_for_mobile | 8.0.1.5 |
| ibm | security_access_manager_firmware | 9.0.1.0 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5 |
| ibm | cognos_analytics | 11.0.6 |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130733.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.0 |
| ibm | websphere_portal | 8.5 |
| ibm | websphere_portal | 7.0 |
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.2.1 |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130808.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from being updated correctly. IBM X-Force ID: 130809.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force ID: 130812.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | * |
IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored credentials. IBM X-Force ID: 130914.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130915.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_requirements_composer | 5.0 |
| ibm | rational_requirements_composer | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_requirements_composer | 5.0.2 |
| ibm | rational_requirements_composer | 4.0.7 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_requirements_composer | 4.0 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling File Gateway 2.2 could allow an authenticated user to change other user's passwords. IBM X-Force ID: 131290.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.7.2 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.6.3 |
| ibm | api_connect | 5.0.6.4 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_connect | 5.0.7.1 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 4.2.5 |
| ibm | infosphere_biginsights | 4.2.0 |
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131397.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 4.2.5 |
| ibm | infosphere_biginsights | 4.2.0 |
IBM Infosphere BigInsights 4.2.0 and 4.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131398.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_biginsights | 4.2.5 |
| ibm | infosphere_biginsights | 4.2.0 |
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.2.0 |
| ibm | api_connect | 5.0.1.0 |
| ibm | api_connect | 5.0.4.0 |
| ibm | api_connect | 5.0.7.2 |
| ibm | api_connect | 5.0.6.0 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.6.3 |
| ibm | api_connect | 5.0.6.4 |
| ibm | api_connect | 5.0.0.0 |
| ibm | api_connect | 5.0.0.1 |
| ibm | api_connect | 5.0.5.0 |
| ibm | api_connect | 5.0.6.2 |
| ibm | api_connect | 5.0.7.1 |
| ibm | api_connect | 5.0.3.0 |
| ibm | api_connect | 5.0.6.1 |
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.7.2 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.7.1 |
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 9.0.2 |
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
| ibm | maximo_asset_management | 7.5 |
| ibm | maximo_asset_management_essentials | 7.5 |
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131759.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131761.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131763.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131764.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131765.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131778.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 8.0.0.9 |
| ibm | websphere_commerce | 8.0.4.0 |
| ibm | websphere_commerce | 8.0.0.6 |
| ibm | websphere_commerce | 7.0.0.2 |
| ibm | websphere_commerce | 8.0.0.3 |
| ibm | websphere_commerce | 8.0.1.12 |
| ibm | websphere_commerce | 8.0.1.2 |
| ibm | websphere_commerce | 8.0.3.3 |
| ibm | websphere_commerce | 8.0.0.15 |
| ibm | websphere_commerce | 8.0.0.13 |
| ibm | websphere_commerce | 8.0.0.10 |
| ibm | websphere_commerce | 7.0.0.1 |
| ibm | websphere_commerce | 8.0.1.8 |
| ibm | websphere_commerce | 8.0.4.3 |
| ibm | websphere_commerce | 7.0.0.4 |
| ibm | websphere_commerce | 8.0.3.1 |
| ibm | websphere_commerce | 8.0.1.4 |
| ibm | websphere_commerce | 8.0.0.0 |
| ibm | websphere_commerce | 8.0.0.19 |
| ibm | websphere_commerce | 8.0.3.4 |
| ibm | websphere_commerce | 8.0.1.5 |
| ibm | websphere_commerce | 8.0.1.9 |
| ibm | websphere_commerce | 8.0.4.2 |
| ibm | websphere_commerce | 8.0.0.14 |
| ibm | websphere_commerce | 8.0.4.1 |
| ibm | websphere_commerce | 8.0.1.7 |
| ibm | websphere_commerce | 8.0.4.4 |
| ibm | websphere_commerce | 7.0.0.6 |
| ibm | websphere_commerce | 7.0.0.7 |
| ibm | websphere_commerce | 7.0.0.3 |
| ibm | websphere_commerce | 8.0.0.4 |
| ibm | websphere_commerce | 8.0.0.7 |
| ibm | websphere_commerce | 8.0.1.1 |
| ibm | websphere_commerce | 8.0.0.1 |
| ibm | websphere_commerce | 7.0.0.5 |
| ibm | websphere_commerce | 8.0.1.10 |
| ibm | websphere_commerce | 8.0.3.2 |
| ibm | websphere_commerce | 8.0.1.0 |
| ibm | websphere_commerce | 7.0.0.8 |
| ibm | websphere_commerce | 8.0.0.2 |
| ibm | websphere_commerce | 8.0.0.8 |
| ibm | websphere_commerce | 8.0.4.5 |
| ibm | websphere_commerce | 8.0.1.11 |
| ibm | websphere_commerce | 8.0.3.0 |
| ibm | websphere_commerce | 8.0.0.16 |
| ibm | websphere_commerce | 8.0.0.11 |
| ibm | websphere_commerce | 8.0.1.13 |
| ibm | websphere_commerce | 8.0.1.6 |
| ibm | websphere_commerce | 8.0.0.5 |
| ibm | websphere_commerce | 7.0.0.0 |
| ibm | websphere_commerce | 8.0.1.3 |
| ibm | websphere_commerce | 8.0.0.12 |
| ibm | websphere_commerce | 8.0.0.18 |
| ibm | websphere_commerce | 8.0.0.17 |
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 131852.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.7 |
| ibm | rational_quality_manager | 4.0.6 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_team_concert | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.7 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_quality_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_team_concert | 4.0.1 |
| ibm | rational_team_concert | 4.0.5 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_team_concert | 4.0.2 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_collaborative_lifecycle_management | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0.7 |
| ibm | rational_collaborative_lifecycle_management | 4.0.3 |
| ibm | rational_software_architect_design_manager | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.7 |
| ibm | rational_doors_next_generation | 4.0.2 |
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_rhapsody_design_manager | 4.0.7 |
| ibm | rational_engineering_lifecycle_manager | 5.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0 |
| ibm | rational_engineering_lifecycle_manager | 6.0.3 |
| ibm | rational_team_concert | 6.0.4 |
| ibm | rational_team_concert | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 4.0.2 |
| ibm | rational_quality_manager | 4.0.1 |
| ibm | rational_team_concert | 4.0.6 |
| ibm | rational_engineering_lifecycle_manager | 4.0.5 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_engineering_lifecycle_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_doors_next_generation | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_quality_manager | 4.0.4 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_engineering_lifecycle_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 4.0.3 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_quality_manager | 4.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.1 |
| ibm | rational_collaborative_lifecycle_management | 4.0.4 |
| ibm | rational_team_concert | 4.0.0.1 |
| ibm | rational_engineering_lifecycle_manager | 4.0.3 |
| ibm | rational_engineering_lifecycle_manager | 4.0.4 |
| ibm | rational_software_architect_design_manager | 4.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 4.0.0.1 |
| ibm | rational_quality_manager | 4.0.0.2 |
| ibm | rational_team_concert | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0 |
| ibm | rational_quality_manager | 4.0.7 |
| ibm | rational_rhapsody_design_manager | 4.0.6 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_software_architect_design_manager | 5.0 |
| ibm | rational_software_architect_design_manager | 4.0.4 |
| ibm | rational_team_concert | 6.0.2 |
| ibm | rational_doors_next_generation | 4.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_team_concert | 4.0.7 |
| ibm | rational_team_concert | 6.0 |
| ibm | rational_software_architect_design_manager | 4.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0.1 |
| ibm | rational_rhapsody_design_manager | 4.0.2 |
| ibm | rational_team_concert | 4.0.0.2 |
| ibm | rational_rhapsody_design_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_team_concert | 4.0 |
| ibm | rational_doors_next_generation | 4.0.5 |
| ibm | rational_collaborative_lifecycle_management | 4.0 |
| ibm | rational_team_concert | 6.0.3 |
| ibm | rational_engineering_lifecycle_manager | 6.0.4 |
| ibm | rational_doors_next_generation | 4.0.6 |
| ibm | rational_doors_next_generation | 4.0.3 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 4.0 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_software_architect_design_manager | 4.0.5 |
| ibm | rational_engineering_lifecycle_manager | 6.0 |
| ibm | rational_team_concert | 4.0.4 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 4.0 |
| ibm | rational_quality_manager | 4.0.5 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_team_concert | 5.0.1 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
CVSS 2.0
Severity: LOW
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algorithms that could allow a local attacker to decrypt highly sensitive information. IBM X-Force ID: 132032.
CVSS 2.0
Severity: LOW
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | * |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | liberty | 3.13 |
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | 7.5.0.0 |
| ibm | datapower_gateway | 7.5.2.1 |
| ibm | datapower_gateway | 7.0.0.15 |
| ibm | datapower_gateway | 7.2.0.8 |
| ibm | datapower_gateway | 7.1.0.7 |
| ibm | datapower_gateway | 7.1.0.15 |
| ibm | datapower_gateway | 7.2.0.10 |
| ibm | datapower_gateway | 7.5.0.9 |
| ibm | datapower_gateway | 7.2.0.2 |
| ibm | datapower_gateway | 7.1.0.6 |
| ibm | datapower_gateway | 7.5.2.3 |
| ibm | datapower_gateway | 7.0.0.4 |
| ibm | datapower_gateway | 7.5.2.7 |
| ibm | datapower_gateway | 7.0.0.8 |
| ibm | datapower_gateway | 7.0.0.17 |
| ibm | datapower_gateway | 7.2.0.5 |
| ibm | datapower_gateway | 7.0.0.9 |
| ibm | datapower_gateway | 7.0.0.10 |
| ibm | datapower_gateway | 7.0.0.2 |
| ibm | datapower_gateway | 7.0.0.14 |
| ibm | datapower_gateway | 7.1.0.12 |
| ibm | datapower_gateway | 7.2.0.7 |
| ibm | datapower_gateway | 7.1.0.4 |
| ibm | datapower_gateway | 7.1.0.17 |
| ibm | datapower_gateway | 7.5.0.2 |
| ibm | datapower_gateway | 7.2.0.13 |
| ibm | datapower_gateway | 7.5.0.4 |
| ibm | datapower_gateway | 7.5.1.5 |
| ibm | datapower_gateway | 7.0.0.5 |
| ibm | datapower_gateway | 7.5.2.5 |
| ibm | datapower_gateway | 7.0.0.6 |
| ibm | datapower_gateway | 7.2.0.9 |
| ibm | datapower_gateway | 7.5.0.7 |
| ibm | datapower_gateway | 7.5.1.2 |
| ibm | datapower_gateway | 7.5.2.0 |
| ibm | datapower_gateway | 7.5.1.6 |
| ibm | datapower_gateway | 7.5.1.1 |
| ibm | datapower_gateway | 7.5.1.3 |
| ibm | datapower_gateway | 7.5.2.6 |
| ibm | datapower_gateway | 7.0.0.3 |
| ibm | datapower_gateway | 7.1.0.3 |
| ibm | datapower_gateway | 7.5.0.5 |
| ibm | datapower_gateway | 7.0.0.7 |
| ibm | datapower_gateway | 7.2.0.3 |
| ibm | datapower_gateway | 7.2.0.15 |
| ibm | datapower_gateway | 7.2.0.0 |
| ibm | datapower_gateway | 7.0.0.13 |
| ibm | datapower_gateway | 7.6.0.0 |
| ibm | datapower_gateway | 7.1.0.13 |
| ibm | datapower_gateway | 7.5.1.4 |
| ibm | datapower_gateway | 7.1.0.18 |
| ibm | datapower_gateway | 7.1.0.8 |
| ibm | datapower_gateway | 7.5.0.6 |
| ibm | datapower_gateway | 7.0.0.0 |
| ibm | datapower_gateway | 7.1.0.10 |
| ibm | datapower_gateway | 7.2.0.4 |
| ibm | datapower_gateway | 7.5.0.1 |
| ibm | datapower_gateway | 7.2.0.1 |
| ibm | datapower_gateway | 7.2.0.6 |
| ibm | datapower_gateway | 7.5.0.3 |
| ibm | datapower_gateway | 7.2.0.12 |
| ibm | datapower_gateway | 7.0.0.11 |
| ibm | datapower_gateway | 7.1.0.11 |
| ibm | datapower_gateway | 7.0.0.18 |
| ibm | datapower_gateway | 7.1.0.14 |
| ibm | datapower_gateway | 7.5.2.2 |
| ibm | datapower_gateway | 7.1.0.1 |
| ibm | datapower_gateway | 7.5.2.4 |
| ibm | datapower_gateway | 7.1.0.9 |
| ibm | datapower_gateway | 7.5.1.0 |
| ibm | datapower_gateway | 7.0.0.19 |
| ibm | datapower_gateway | 7.5.1.8 |
| ibm | datapower_gateway | 7.1.0.2 |
| ibm | datapower_gateway | 7.1.0.16 |
| ibm | datapower_gateway | 7.5.1.7 |
| ibm | datapower_gateway | 7.0.0.12 |
| ibm | datapower_gateway | 7.2.0.14 |
| ibm | datapower_gateway | 7.1.0.0 |
| ibm | datapower_gateway | 7.0.0.16 |
| ibm | datapower_gateway | 7.2.0.11 |
| ibm | datapower_gateway | 7.1.0.5 |
| ibm | datapower_gateway | 7.5.0.8 |
| ibm | datapower_gateway | 7.0.0.1 |
| ibm | datapower_gateway | 7.5.2.8 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132493.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132494.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132613.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 10.0 |
| ibm | security_guardium_database_activity_monitor | 10.1.2 |
| ibm | security_guardium_database_activity_monitor | 10.1.4 |
| ibm | security_guardium_database_activity_monitor | 10.0.1 |
| ibm | security_guardium_database_activity_monitor | 10.1 |
| ibm | security_guardium_database_activity_monitor | 10.1.3 |
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-552,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_team_concert | 5.0.2 |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_engineering_lifecycle_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
| ibm | rational_quality_manager | * |
| ibm | rational_team_concert | 5.0.0 |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_engineering_lifecycle_manager | 5.0.1 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_doors_next_generation | 5.0.0 |
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_team_concert | 5.0.1 |
IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132851.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_anywhere | 7.6.1.0 |
| ibm | maximo_anywhere | 7.5.2.1 |
| ibm | maximo_anywhere | 7.6.2.0 |
| ibm | maximo_anywhere | 7.5.1.2 |
| ibm | maximo_anywhere | 7.5.2.2 |
| ibm | maximo_anywhere | 7.6.0.0 |
| ibm | maximo_anywhere | 7.5.2.0 |
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.0.4 |
| ibm | financial_transaction_manager | 3.0.0.2 |
| ibm | financial_transaction_manager | 3.0.0.5 |
| ibm | financial_transaction_manager | 3.0.0.6 |
| ibm | financial_transaction_manager | 3.0.0.1 |
| ibm | financial_transaction_manager | 3.0.0.7 |
| ibm | financial_transaction_manager | 3.0.0.0 |
| ibm | financial_transaction_manager | 3.0.0.3 |
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132927.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132928.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132929.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.12 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.5.0.7 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.1.0.0 |
| ibm | websphere_mq | 7.1.0.7 |
| ibm | websphere_mq | 7.1.0.8 |
| ibm | websphere_mq | 9.0.3.0 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 9.0.1.0 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 9.0.2.0 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.1.0.5 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.1.0.4 |
| ibm | websphere_mq | 7.1.0.6 |
| ibm | websphere_mq | 7.0.1.9 |
| ibm | websphere_mq | 7.1.0.2 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 7.0.1.6 |
| ibm | websphere_mq | 7.5.0.6 |
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 7.1.0.3 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.10 |
| ibm | websphere_mq | 7.0.1.11 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 7.1.0.1 |
| ibm | websphere_mq | 7.0.1.13 |
| ibm | websphere_mq | 7.0.1.14 |
| ibm | websphere_mq | 7.5.0.5 |
| ibm | websphere_mq | 7.5.0.8 |
IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center template data. IBM X-Force ID: 132954.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 6.0 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133088.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-force ID: 133120.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.2 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.2.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.7 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.3 |
| ibm | qradar_security_information_and_event_manager | 7.2.6 |
| ibm | qradar_security_information_and_event_manager | 7.2.4 |
| ibm | qradar_security_information_and_event_manager | 7.2.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.5 |
IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 133123.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_pulse | 1.0.3 |
| ibm | qradar_pulse | 1.0.1 |
| ibm | qradar_pulse | 1.0.0 |
| ibm | qradar_pulse | 1.0.2 |
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.6.0.0 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_for_service_management | 1.1.3 |
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133178.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | 2.2 |
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-416,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.2.2.9 |
| ibm | tivoli_monitoring | 6.2.2.3 |
| ibm | tivoli_monitoring | 6.2.2.4 |
| ibm | tivoli_monitoring | 6.2.2.5 |
| ibm | tivoli_monitoring | 6.2.2.8 |
| ibm | tivoli_monitoring | 6.2.2 |
| ibm | tivoli_monitoring | 6.2.2.7 |
| ibm | tivoli_monitoring | 6.2.2.2 |
| ibm | tivoli_monitoring | 6.2.2.6 |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133259.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133260.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133261.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133263.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133268.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | general_parallel_file_system | 4.1.0.4 |
| ibm | spectrum_scale | * |
| ibm | general_parallel_file_system | 4.1.0.7 |
| ibm | spectrum_scale | 5.0.0.0 |
| ibm | general_parallel_file_system | 4.1.0.2 |
| ibm | general_parallel_file_system | 4.1.0.3 |
| ibm | general_parallel_file_system | 4.1.0.0 |
| ibm | general_parallel_file_system | 4.1.0.8 |
| ibm | general_parallel_file_system | 4.1.0.1 |
| ibm | general_parallel_file_system | 4.1.0.6 |
| ibm | general_parallel_file_system | 4.1.0.5 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| debian | debian_linux | 9.0 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 133540.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 133562.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 133638.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133640.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134000.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | openpages_grc_platform | 7.2.0.0 |
| ibm | openpages_grc_platform | 8.0.0.0 |
| ibm | openpages_grc_platform | 7.4.0.0 |
| ibm | openpages_grc_platform | 7.3.0.0 |
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | liberty | * |
IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134004.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 4.5 |
| ibm | connections | 5.5 |
| ibm | connections | 6.0 |
| ibm | connections | 4.0 |
IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134005.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections_engagement_center | 6.0 |
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134063.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134064.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134065.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_collaborative_lifecycle_management | 6.0 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_quality_manager | 6.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_quality_manager | 5.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_collaborative_lifecycle_management | 5.0 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134066.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-613,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 9.0.0.8 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 10.0.0.3 |
| ibm | integration_bus | 9.0.0.7 |
| ibm | integration_bus | 10.0.0.6 |
| ibm | integration_bus | 10.0.0.5 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | integration_bus | 10.0.0.9 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | integration_bus | 10.0.0.8 |
| ibm | integration_bus | 10.0.0.0 |
| ibm | integration_bus | 10.0.0.7 |
| ibm | integration_bus | 10.0 |
| ibm | integration_bus | 9.0.0.6 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | integration_bus | 9.0.0.0 |
| ibm | integration_bus | 10.0.0.1 |
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integration_bus | 9.0.0.8 |
| ibm | integration_bus | 10.0.0.4 |
| ibm | integration_bus | 9.0.0.2 |
| ibm | integration_bus | 9.0.0.9 |
| ibm | integration_bus | 10.0.0.3 |
| ibm | integration_bus | 9.0.0.7 |
| ibm | integration_bus | 10.0.0.6 |
| ibm | integration_bus | 10.0.0.5 |
| ibm | integration_bus | 10.0.0.2 |
| ibm | integration_bus | 10.0.0.9 |
| ibm | integration_bus | 9.0.0.5 |
| ibm | integration_bus | 9.0.0.4 |
| ibm | integration_bus | 10.0.0.8 |
| ibm | integration_bus | 10.0.0.0 |
| ibm | integration_bus | 10.0.0.7 |
| ibm | integration_bus | 9.0.0.6 |
| ibm | integration_bus | 9.0.0.1 |
| ibm | integration_bus | 9.0.0.3 |
| ibm | integration_bus | 9.0.0.0 |
| ibm | integration_bus | 10.0.0.1 |
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | * |
IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 134178.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
CVSS 2.0
Severity: LOW
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 9.0.2 |
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) could allow an authenticated user to cause a denial of service due to incorrect authorization for resource intensive scenarios. IBM X-Force ID: 134392.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 134393.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_team_concert | * |
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.0 |
A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-Force ID: 134531.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | 8.1 |
| ibm | san_volume_controller_firmware | 8.1 |
| ibm | storwize_v7000_firmware | 8.1 |
| ibm | flashsystem_v9000_firmware | 8.1 |
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.1.0 |
| ibm | notes | 8.5.0.0 |
| ibm | notes | 8.5.3.0 |
| ibm | notes | 8.5.2.0 |
| ibm | notes | 9.0.0.0 |
| ibm | client_application_access | 1.0.1.1 |
| ibm | notes | 8.5.1.0 |
| ibm | notes | 9.0.1.0 |
| ibm | client_application_access | 1.0.1.2 |
IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_streams | 4.2.1 |
IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.1.0 |
| ibm | notes | 8.5.0.0 |
| ibm | notes | 8.5.3.0 |
| ibm | notes | 8.5.2.0 |
| ibm | notes | 9.0.0.0 |
| ibm | client_application_access | 1.0.1.1 |
| ibm | notes | 8.5.1.0 |
| ibm | notes | 9.0.1.0 |
| ibm | client_application_access | 1.0.1.2 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134637.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.
CVSS 2.0
Severity: LOW
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_workload_scheduler | 9.2 |
| ibm | tivoli_workload_scheduler | 8.6 |
| ibm | tivoli_workload_scheduler | 9.1 |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134796.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | 6.0.3 |
| ibm | rational_quality_manager | 5.0.0 |
| ibm | rational_collaborative_lifecycle_management | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.1 |
| ibm | rational_quality_manager | 5.0.2 |
| ibm | rational_collaborative_lifecycle_management | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 5.0.0 |
| ibm | rational_quality_manager | 6.0.2 |
| ibm | rational_collaborative_lifecycle_management | 5.0.1 |
| ibm | rational_quality_manager | 6.0.0 |
| ibm | rational_quality_manager | 5.0.1 |
| ibm | rational_quality_manager | 6.0.1 |
| ibm | rational_quality_manager | 6.0.5 |
| ibm | rational_collaborative_lifecycle_management | 6.0.0 |
| ibm | rational_quality_manager | 6.0.3 |
| ibm | rational_quality_manager | 6.0.4 |
| ibm | rational_collaborative_lifecycle_management | 6.0.4 |
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.1.0 |
| ibm | notes | 8.5.0.0 |
| ibm | notes | 8.5.3.0 |
| ibm | notes | 8.5.2.0 |
| ibm | notes | 9.0.0.0 |
| ibm | client_application_access | 1.0.1.1 |
| ibm | notes | 8.5.1.0 |
| ibm | notes | 9.0.1.0 |
| ibm | client_application_access | 1.0.1.2 |
IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | * |
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | * |
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_network_insights | * |
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
| ibm | qradar_network_insights | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_network_insights | 7.3.0 |
| ibm | qradar_network_insights | 7.3.1 |
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_risk_manager | 7.3.0 |
| ibm | qradar_network_insights | * |
| ibm | qradar_risk_manager | * |
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
| ibm | qradar_network_insights | 7.2.8 |
| ibm | qradar_risk_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | * |
| ibm | qradar_risk_manager | 7.2.8 |
| ibm | qradar_vulnerability_manager | * |
| ibm | qradar_vulnerability_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_vulnerability_manager | 7.2.8 |
| ibm | qradar_network_insights | 7.3.0 |
| ibm | qradar_vulnerability_manager | 7.3.0 |
| ibm | qradar_network_insights | 7.3.1 |
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) contain an undisclosed vulnerability with the potential for information disclosure. IBM X-Force ID: 134820.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 2.5.0.5 |
| ibm | security_key_lifecycle_manager | 2.5.0.8 |
| ibm | security_key_lifecycle_manager | 2.7.0 |
| ibm | security_key_lifecycle_manager | 2.7.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.1 |
| ibm | security_key_lifecycle_manager | 2.5.0.3 |
| ibm | security_key_lifecycle_manager | 2.6.0 |
| ibm | security_key_lifecycle_manager | 2.5.0.7 |
| ibm | security_key_lifecycle_manager | 2.7.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.3 |
| ibm | security_key_lifecycle_manager | 2.5.0.6 |
| ibm | security_key_lifecycle_manager | 2.5.0.2 |
| ibm | security_key_lifecycle_manager | 2.5.0.4 |
| ibm | security_key_lifecycle_manager | 2.6.0.1 |
| ibm | security_key_lifecycle_manager | 2.6.0.2 |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134909.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 134913.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager_for_enterprise_single_sign-on | 8.2.2 |
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) stores potentially sensitive information in a cache that could be read by authenticated users. IBM X-Force ID: 134915.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges. IBM X-Force ID: 134919.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134921.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.1.1.5 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.2.0.5 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.6 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 7.0.1.1 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.1.0.5 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 7.0.0.2 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.1.1.6 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 7.0.1.0 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134922.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.1.0.2 |
| ibm | curam_social_program_management | 6.1.0.4 |
| ibm | curam_social_program_management | 6.0.5.9 |
| ibm | curam_social_program_management | 6.1.0.1 |
| ibm | curam_social_program_management | 6.1.1.5 |
| ibm | curam_social_program_management | 6.2.0.3 |
| ibm | curam_social_program_management | 6.0.5.10 |
| ibm | curam_social_program_management | 6.2.0.5 |
| ibm | curam_social_program_management | 6.0.5.5 |
| ibm | curam_social_program_management | 6.2.0.0 |
| ibm | curam_social_program_management | 6.0.5.2 |
| ibm | curam_social_program_management | 6.0.5.1 |
| ibm | curam_social_program_management | 6.2.0.6 |
| ibm | curam_social_program_management | 6.2.0.2 |
| ibm | curam_social_program_management | 6.1.1.2 |
| ibm | curam_social_program_management | 7.0.1.1 |
| ibm | curam_social_program_management | 6.0.5.3 |
| ibm | curam_social_program_management | 6.2.0.1 |
| ibm | curam_social_program_management | 7.0.0.1 |
| ibm | curam_social_program_management | 6.1.0.5 |
| ibm | curam_social_program_management | 6.0.5.4 |
| ibm | curam_social_program_management | 7.0.0.2 |
| ibm | curam_social_program_management | 6.1.0.3 |
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 6.1.1.6 |
| ibm | curam_social_program_management | 6.0.5.0 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.1.1.3 |
| ibm | curam_social_program_management | 6.2.0.4 |
| ibm | curam_social_program_management | 6.0.5.8 |
| ibm | curam_social_program_management | 7.0.2.0 |
| ibm | curam_social_program_management | 6.0.5.7 |
| ibm | curam_social_program_management | 7.0.1.0 |
| ibm | curam_social_program_management | 6.0.5.6 |
| ibm | curam_social_program_management | 6.1.0.0 |
| ibm | curam_social_program_management | 6.1.1.4 |
| ibm | curam_social_program_management | 6.1.1.1 |
| ibm | curam_social_program_management | 7.0.0.0 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_for_service_management | 1.1.3 |
A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications consuming messages that it needs to perform data conversion on. IBM X-Force ID: 135520.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 9.0.4 |
| ibm | websphere_mq | 9.0.2 |
| ibm | websphere_mq | 9.0.0.2 |
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0.0.0 |
| ibm | connections | 5.5.0.0 |
| ibm | connections | 6.0 |
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | * |
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 6.0.5 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
| ibm | jazz_reporting_service | 6.0.4 |
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10.0.0 |
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | urbancode_deploy | * |
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.
CVSS 2.0
Severity: LOW
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands into malicious files that could be executed by the administrator. IBM X-Force ID: 135855.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.1 |
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.3 |
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere | 7.2.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere | 7.2.0.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager_enterprise_service_bus | 8.6.0.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | websphere | 7.2.0.2 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere | 7.2.0.1 |
| ibm | websphere | 7.2.0.3 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | websphere | 7.2.0.5 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.0.1 |
| ibm | security_guardium | 10.0 |
| ibm | security_guardium | 10.1.3 |
| ibm | security_guardium | 10.1.2 |
| ibm | security_guardium | 10.1.0 |
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | transformation_extender_advanced | 9.0 |
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | control_center | 6.1.1.0 |
| ibm | financial_transaction_manager | 3.0.4.0 |
| ibm | control_center | 6.0.0.1 |
| ibm | control_center | 6.0.0.0 |
| ibm | financial_transaction_manager | 3.0.2.1 |
| ibm | control_center | 6.1.0.0 |
| ibm | financial_transaction_manager | 3.0.3.0 |
| ibm | control_center | 6.1.0.1 |
| ibm | financial_transaction_manager | 3.1.0.0 |
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Force ID: 126454.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 7.5.0.7 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 7.5.0.5 |
| ibm | websphere_mq | 7.5.0.8 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 9.0.2 |
| ibm | websphere_mq | 7.5.0.6 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_business_intelligence | 10.2.1 |
| ibm | cognos_business_intelligence | 10.2 |
| ibm | cognos_business_intelligence | 10.2.1.1 |
| ibm | cognos_business_intelligence | 10.2.2 |
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager_enterprise_service_bus | 8.6.0.0 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | business_process_manager | 8.5.0.0 |
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.6.0.0 |
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | business_process_manager | 8.6.0.0 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| kde | trojita | - |
| microsoft | outlook | 2010 |
| gmail | - | |
| kde | kmail | - |
| ibm | notes | - |
| emclient | emclient | - |
| flipdogsolutions | maildroid | - |
| horde | horde_imp | - |
| gnome | evolution | - |
| microsoft | outlook | 2007 |
| microsoft | outlook | 2013 |
| freron | mailmate | - |
| r2mail2 | r2mail2 | - |
| apple | - | |
| ritlabs | the_bat | - |
| microsoft | outlook | 2016 |
| bloop | airmail | - |
| 9folders | nine | - |
| postbox-inc | postbox | - |
| mozilla | thunderbird | - |
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.6.0.0 |
IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136786.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mobilefirst_platform_foundation | 8.0.0.0 |
| ibm | mobilefirst_platform_foundation | 6.3.0.0 |
| ibm | mobilefirst_platform_foundation | 7.0.0.0 |
| ibm | mobilefirst_platform_foundation | 7.1.0.0 |
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-345,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 136818.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5.0 |
| ibm | cognos_analytics | 11.0.6.0 |
| netapp | oncommand_insight | - |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.7.0 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5.0 |
| ibm | cognos_analytics | 11.0.6.0 |
| netapp | oncommand_insight | - |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.7.0 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cognos_analytics | 11.0.5.0 |
| ibm | cognos_analytics | 11.0.6.0 |
| netapp | oncommand_insight | - |
| ibm | cognos_analytics | 11.0.1 |
| ibm | cognos_analytics | 11.0.3 |
| ibm | cognos_analytics | 11.0.7.0 |
| ibm | cognos_analytics | 11.0.2 |
| ibm | cognos_analytics | 11.0.0 |
| ibm | cognos_analytics | 11.0.4 |
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.7.2 |
| ibm | api_connect | 5.0.8.1 |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.7.1 |
| ibm | api_connect | 5.0.8.0 |
IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user to consume all resources due to a memory leak resulting in service loss. IBM X-Force ID: 136975.
CVSS 2.0
Severity: LOW
Problem Type: CWE-772,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022.
CVSS 2.0
Severity: LOW
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 2.1.2 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.5 |
IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.6 |
| ibm | tivoli_monitoring | 6.2.3 |
| ibm | tivoli_monitoring | 6.3.0.1 |
| ibm | tivoli_monitoring | 6.2.3.1 |
| ibm | tivoli_monitoring | 6.2.3.5 |
| ibm | tivoli_monitoring | 6.3.0.5 |
| ibm | tivoli_monitoring | 6.2.3.3 |
| ibm | tivoli_monitoring | 6.3.0 |
| ibm | tivoli_monitoring | 6.3.0.3 |
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.2.3.2 |
| ibm | tivoli_monitoring | 6.2.3.4 |
| ibm | tivoli_monitoring | 6.3.0.2 |
| ibm | tivoli_monitoring | 6.3.0.4 |
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | 5.0 |
| ibm | rational_requirements_composer | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.5 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_requirements_composer | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137037.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137038.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | * |
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq_managed_file_transfer | 9.0.3 |
| ibm | websphere_mq_managed_file_transfer | 7.5.0.0 |
| ibm | websphere_mq_managed_file_transfer | * |
| ibm | websphere_mq_managed_file_transfer | 9.0.1 |
| ibm | websphere_mq_managed_file_transfer | 9.0.4 |
| ibm | websphere_mq_managed_file_transfer | 9.0.2 |
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | integrated_management_module_firmware | * |
| lenovo | integrated_management_module_firmware | * |
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | g8272_firmware | * |
| ibm | g8332_firmware | * |
| ibm | layer_2/3_copper_firmware | * |
| lenovo | g8264_firmware | * |
| ibm | virtual_fabric_10gb | * |
| lenovo | g8332_firmware | * |
| lenovo | g8052_firmware | * |
| ibm | fabric_cn4093_10gb_firmware | * |
| ibm | g8264cs_firmware | * |
| lenovo | g8124e_firmware | * |
| ibm | 1:10g_firmware | * |
| lenovo | si4091_firmware | * |
| ibm | g8124e_firmware | * |
| ibm | g8316_firmware | * |
| ibm | 1g_l2-7_slb | * |
| lenovo | fabric_cn4093_10gb_firmware | * |
| ibm | g8264t_firmware | * |
| ibm | en2092_1gb_firmware | * |
| ibm | g8124_firmware | * |
| ibm | g8264_firmware | * |
| lenovo | g8296_firmware | * |
| lenovo | fabric_en4093r_10gb_firmware | * |
| ibm | g8052_firmware | * |
| lenovo | g8264cs_firmware | * |
| ibm | fabric_en4093/en4093r_10gb_firmware | * |
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI and other tools can exhaust available system memory which can cause the IMM2 to reboot itself until the requests cease.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenova | flex_system_x240_m5_firmware | * |
| lenova | flex_system_x480_x6_firmware | * |
| ibm | system_x3250_m4_firmware | * |
| lenova | flex_system_x880_firmware | * |
| ibm | system_x3500_m4_firmware | * |
| ibm | system_x3550_m4_firmware | * |
| lenova | system_x3750_m4_firmware | * |
| ibm | bladecenter_hs22_firmware | * |
| lenova | flex_system_x240_m4_firmware | * |
| ibm | nextscale_nx360_m4_firmware | * |
| ibm | system_x3950_x6_firmware | * |
| ibm | system_x3650_m4_bd_firmware | * |
| ibm | system_x3650_m4_firmware | * |
| ibm | flex_system_x280_m4_firmware | * |
| lenova | system_x3850_x6_firmware | * |
| ibm | flex_system_x880_m4_firmware | * |
| ibm | system_x3650_m4_hd_firmware | * |
| lenova | flex_system_x280_x6_firmware | * |
| ibm | system_x3750_m4_firmware | * |
| ibm | system_x3530_m4_firmware | * |
| lenova | system_x3250_m6_firmware | * |
| ibm | flex_system_x480_m4_firmware | * |
| ibm | system_x3100_m4_firmware | * |
| ibm | system_x3630_m4_firmware | * |
| ibm | idataplex_dx360_m4_firmware | * |
| ibm | system_x3250_m5_firmware | * |
| ibm | flex_system_x220_m4_firmware | * |
| lenova | flex_system_x440_m4_firmware | * |
| lenova | system_x3500_m5_firmware | * |
| lenova | system_x3950_x6_firmware | * |
| lenova | nextscale_nx360_m5_firmware | * |
| ibm | flex_system_x440_m4_firmware | * |
| ibm | flex_system_x222_m4_firmware | * |
| ibm | flex_system_x240_m4_firmware | * |
| ibm | bladecenter_hs23e_firmware | * |
| ibm | system_x3100_m5_firmware | * |
| lenova | system_x3550_m5_firmware | * |
| ibm | idataplex_dx360_m4_water_cooled_firmware | * |
| lenova | system_x3650_m5_firmware | * |
| ibm | system_x3850_x6_firmware | * |
| ibm | system_x3300_m4_firmware | * |
| ibm | bladecenter_hs23_firmware | * |
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-755,CWE-755,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | 7.8.1.0 |
| oracle | weblogic_server | 10.3.6.0.0 |
| oracle | weblogic_server | 12.2.1.2.0 |
| lenovo | storage_v5030_firmware | 7.7.1.6 |
| arubanetworks | clearpass_policy_manager | * |
| ibm | storwize_v5000_firmware | 7.7.1.6 |
| ibm | storwize_v7000_firmware | 7.8.1.0 |
| ibm | storwize_v7000_firmware | 7.7.1.6 |
| netapp | oncommand_balance | - |
| oracle | weblogic_server | 12.1.3.0.0 |
| hp | server_automation | 10.1.0 |
| hp | server_automation | 10.0.0 |
| hp | server_automation | 10.2.0 |
| oracle | weblogic_server | 12.2.1.1.0 |
| hp | server_automation | 10.5.0 |
| apache | struts | * |
| ibm | storwize_v3500_firmware | 7.7.1.6 |
| ibm | storwize_v3500_firmware | 7.8.1.0 |
| lenovo | storage_v5030_firmware | 7.8.1.0 |
| hp | server_automation | 9.1.0 |
Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | kitura | * |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated user to withdraw other user's submitted applications from the system and possibly obtain privileges. IBM X-Force ID: 137380.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 6.0.5 |
| ibm | curam_social_program_management | 7.0.1 |
| ibm | curam_social_program_management | 6.1.1.0 |
| ibm | curam_social_program_management | 6.2.0.0 |
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | 6.0.3 |
| ibm | jazz_reporting_service | 6.0.5 |
| ibm | jazz_reporting_service | 5.0.2 |
| ibm | jazz_reporting_service | 6.0 |
| ibm | jazz_reporting_service | 6.0.2 |
| ibm | jazz_reporting_service | 6.0.1 |
| ibm | jazz_reporting_service | 5.0 |
| ibm | jazz_reporting_service | 5.0.1 |
| ibm | jazz_reporting_service | 6.0.4 |
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.2 |
| ibm | content_navigator | 3.0.3 |
| ibm | content_navigator | 2.0.3 |
IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.1 |
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 3.0.2 |
| ibm | content_navigator | 2.0.2.7 |
| ibm | content_navigator | 3.0.3 |
| ibm | content_navigator | 2.0.2.8 |
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765.
CVSS 2.0
Severity: LOW
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_database_activity_monitor | 9.1 |
| ibm | security_guardium_database_activity_monitor | 9.0 |
| ibm | security_guardium_database_activity_monitor | 9.5 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 137767.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 137769.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. IBM X-Force ID: 137771.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.8 |
| ibm | websphere_mq | 9.0.4 |
| ibm | websphere_mq | 9.0.0.2 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 137773.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-307,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connecting to a Queue Manager could cause a SIGSEGV in the Channel process amqrmppa. IBM X-Force ID: 137775.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 8.0.0.0 |
| ibm | websphere_mq | 7.5.0.1 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 7.5 |
| ibm | websphere_mq | 7.1.0.7 |
| ibm | websphere_mq | 7.1.0.8 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 7.5.0.2 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 7.1.0.5 |
| ibm | websphere_mq | 7.5.0.3 |
| ibm | websphere_mq | 7.1.0.4 |
| ibm | websphere_mq | 7.1.0.6 |
| ibm | websphere_mq | 9.0.0.0 |
| ibm | websphere_mq | 7.1.0.2 |
| ibm | websphere_mq | 9.0.4 |
| ibm | websphere_mq | 7.1.0.9 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 7.1.0.3 |
| ibm | websphere_mq | 7.5.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 7.1 |
| ibm | websphere_mq | 8.0.0.8 |
| ibm | websphere_mq | 9.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 9.0.0 |
| ibm | websphere_mq | 7.1.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 9.0.2 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 137776.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137777.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 11.4 |
| ibm | infosphere_master_data_management | 11.5 |
| ibm | infosphere_master_data_management | 11.6 |
IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138079.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.7.2 |
| ibm | api_connect | 5.0.8.1 |
| ibm | api_connect | * |
| ibm | api_connect | 5.0.7.0 |
| ibm | api_connect | 5.0.7.1 |
| ibm | api_connect | 5.0.8.0 |
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 6.1.8 |
| ibm | aix | 6.1.3 |
| ibm | aix | 7.1.2 |
| ibm | aix | 7.1.4 |
| ibm | aix | 6.1 |
| ibm | aix | 7.2.1 |
| ibm | aix | 7.1 |
| ibm | aix | 7.1.5 |
| ibm | aix | 7.2.2 |
| ibm | aix | 7.1.1 |
| ibm | aix | 6.1.9 |
| ibm | aix | 6.1.1 |
| ibm | aix | 6.1.7 |
| ibm | aix | 6.1.2 |
| ibm | aix | 6.1.5 |
| ibm | aix | 6.1.4 |
| ibm | aix | 6.1.6 |
| ibm | aix | 7.1.3 |
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.0.1.2 |
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.0.1.1 |
| ibm | websphere_process_server | 7.0.0.4 |
| ibm | websphere_enterprise_service_bus | 7.0.0.4 |
| ibm | business_process_manager | 7.5.1.0 |
| ibm | websphere_enterprise_service_bus | 7.0.0.5 |
| ibm | websphere_process_server | 7.0.0.2 |
| ibm | websphere_process_server | 7.0.0.3 |
| ibm | business_process_manager | 8.0.1.0 |
| ibm | business_process_manager | 7.5.1.2 |
| ibm | business_process_manager_enterprise_service_bus | 8.6.0.0 |
| ibm | websphere_enterprise_service_bus | 7.0.0.2 |
| ibm | business_process_manager | 8.0.0.0 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.0.1.3 |
| ibm | websphere_enterprise_service_bus | 7.0.0.1 |
| ibm | websphere_enterprise_service_bus | 7.5.1.2 |
| ibm | websphere_enterprise_service_bus | 7.5.0.0 |
| ibm | business_process_manager | 7.5.0.1 |
| ibm | websphere_enterprise_service_bus | 7.0.0.0 |
| ibm | websphere_process_server | 7.0.0.1 |
| ibm | business_process_manager | 8.5.6.1 |
| ibm | websphere_enterprise_service_bus | 7.5.1.0 |
| ibm | business_process_manager | 8.5.0.2 |
| ibm | business_process_manager | 7.5.1.1 |
| ibm | websphere_enterprise_service_bus | 7.5.1.1 |
| ibm | business_process_manager | 8.5.6.2 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | websphere_process_server | 7.0.0.5 |
| ibm | business_process_manager | 8.5.0.1 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | 8.5.0.0 |
| ibm | websphere_enterprise_service_bus | 7.5.0.1 |
| ibm | websphere_process_server | 7.0 |
| ibm | websphere_enterprise_service_bus | 7.0.0.3 |
| ibm | business_process_manager | 7.5.0.0 |
IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_workload_scheduler | 9.3 |
| ibm | tivoli_workload_scheduler | 9.4 |
| ibm | tivoli_workload_scheduler | 9.2 |
| ibm | tivoli_workload_scheduler | 8.6 |
| ibm | tivoli_workload_scheduler | 9.1 |
IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff who can access to the database of this product. IBM X-Force ID: 138210.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | application_performance_management | 8.1.4.0 |
| ibm | monitoring | 8.1.3.0 |
| ibm | monitoring | 8.1.4.0 |
| ibm | cloud_apm_data_collector | 7.4 |
| ibm | cloud_apm_data_collector | 7.3 |
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 7.0.1.0 |
| ibm | websphere_mq | 7.0.1.7 |
| ibm | websphere_mq | 7.0.1.5 |
| ibm | websphere_mq | 7.0.1.12 |
| ibm | websphere_mq | 7.0.1.1 |
| ibm | websphere_mq | 7.0.1.3 |
| ibm | websphere_mq | 7.0.1.8 |
| ibm | websphere_mq | 7.0.1.10 |
| ibm | websphere_mq | 7.0.1.11 |
| ibm | websphere_mq | 7.0.1.4 |
| ibm | websphere_mq | 7.0.1.2 |
| ibm | websphere_mq | 7.0.1.13 |
| ibm | websphere_mq | 7.0.1.14 |
| ibm | websphere_mq | 7.0.1.9 |
| ibm | websphere_mq | 7.0.1.6 |
IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.5.0 |
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.2.1 |
| ibm | financial_transaction_manager | 3.0.0.0 |
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could cause a denial of service. IBM X-Force ID: 138376.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.4.0 |
| ibm | financial_transaction_manager | 3.1.0.0 |
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.4.0 |
| ibm | financial_transaction_manager | 3.1.0.0 |
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138378.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.6.0 |
Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138427.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138429.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | * |
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138435.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 4.1.5 |
| ibm | daeja_viewone | 5.0.2 |
| ibm | daeja_viewone | 5.0.1 |
| ibm | daeja_viewone | 5.0.3 |
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138439.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138440.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138441.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138445.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.0.1 |
| ibm | notes | 9.0.1.9 |
| ibm | notes | 8.5.1.5 |
| ibm | notes | 8.5.3.6 |
| ibm | notes | 8.5.2.4 |
| ibm | notes | 9.0 |
| ibm | client_application_access | 1.0.1.2 |
| ibm | client_application_access | 1.0.1 |
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138709.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.0.1 |
| ibm | notes | 9.0.1.9 |
| ibm | notes | 8.5.1.5 |
| ibm | notes | 8.5.3.6 |
| ibm | notes | 8.5.2.4 |
| ibm | notes | 9.0 |
| ibm | client_application_access | 1.0.1.2 |
| ibm | client_application_access | 1.0.1 |
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | client_application_access | 1.0.0.1 |
| ibm | notes | 9.0.1.9 |
| ibm | notes | 8.5.1.5 |
| ibm | notes | 8.5.3.6 |
| ibm | notes | 8.5.2.4 |
| ibm | notes | 9.0 |
| ibm | client_application_access | 1.0.1.2 |
| ibm | client_application_access | 1.0.1 |
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| netapp | oncommand_insight | - |
| ibm | cognos_analytics | * |
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management_essentials | 7.5.0.0 |
| ibm | maximo_asset_management | 7.6.0.0 |
| ibm | maximo_asset_management | 7.5.0.0 |
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6.0.8 |
| ibm | maximo_asset_management | 7.6.0.5 |
| ibm | maximo_asset_management | 7.6.0.6 |
| ibm | maximo_asset_management | 7.6.0.7 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138822.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | java_sdk | 6.1.0.0 |
| ibm | java_sdk | 7.1.0.0 |
| ibm | java_sdk | 8.0.0.0 |
| ibm | java_sdk | 6.0.0.0 |
| ibm | java_sdk | 7.0.0.0 |
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | * |
IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM module for authentication, could allow a user to cause a deadlock in the IBM MQ PAM code which could result in a denial of service. IBM X-Force ID: 138949.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 9.0.3 |
| ibm | websphere_mq | 8.0.0.3 |
| ibm | websphere_mq | 8.0.0.4 |
| ibm | websphere_mq | 9.0.0.1 |
| ibm | websphere_mq | 8.0.0.7 |
| ibm | websphere_mq | 8.0.0.8 |
| ibm | websphere_mq | 8.0.0.2 |
| ibm | websphere_mq | 9.0.0.2 |
| ibm | websphere_mq | 8.0.0.6 |
| ibm | websphere_mq | 8.0.0.5 |
| ibm | websphere_mq | 8.0.0.1 |
| ibm | websphere_mq | 9.0.1 |
| ibm | websphere_mq | 8.0 |
| ibm | websphere_mq | 9.0.4 |
| ibm | websphere_mq | 9.0.2 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139025.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 10.1 |
| ibm | marketing_platform | 9.1.2 |
| ibm | marketing_platform | 9.1.0 |
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139003.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium_big_data_intelligence | 3.1 |
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-335,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.
CVSS 2.0
Severity: LOW
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
CVSS 2.0
Severity: LOW
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance | 9.0.2 |
| ibm | mq_appliance | 9.0.4 |
| ibm | mq_appliance | 9.0.3 |
| ibm | mq_appliance | 9.0.1 |
IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139226.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | * |
| ibm | general_parallel_file_system | * |
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,CWE-1021,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 11.7 |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139474.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | notes | 9.0.1.9 |
| ibm | notes | 8.5.2 |
| ibm | notes | 8.5.3 |
| ibm | notes | 8.5.1.5 |
| ibm | notes | 8.5.3.6 |
| ibm | notes | 8.5.0.2 |
| ibm | notes | 9.0.1 |
| ibm | notes | 8.5.2.4 |
| ibm | notes | 8.5.1 |
| ibm | notes | 9.0 |
| ibm | notes | 8.5 |
IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | notes | 9.0.1.9 |
| ibm | notes | 8.5.2 |
| ibm | notes | 8.5.3 |
| ibm | notes | 8.5.1.5 |
| ibm | notes | 8.5.3.6 |
| ibm | notes | 8.5.0.2 |
| ibm | notes | 9.0.1 |
| ibm | notes | 8.5.2.4 |
| ibm | notes | 8.5.1 |
| ibm | notes | 9.0 |
| ibm | notes | 8.5 |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139589.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139595.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139597.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | monitoring | 8.1.3 |
| ibm | monitoring | 8.1.4 |
IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139598.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | monitoring | 8.1.4 |
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_federated_identity_manager | 6.2.1 |
| ibm | security_access_manager | * |
| ibm | tivoli_federated_identity_manager | 6.2.2 |
| ibm | tivoli_federated_identity_manager | 6.2.0 |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | * |
| ibm | websphere_portal | 8.5 |
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-916,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_for_virtual_environments | * |
| ibm | spectrum_protect_for_space_management | * |
| ibm | spectrum_protect_snapshot | * |
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 7.0 |
| ibm | security_identity_manager | 7.0.1 |
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 11.7 |
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 11029.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.2 |
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0 |
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | 5.0.1 |
| ibm | rational_software_architect_design_manager | 5.0.0 |
| ibm | rational_rhapsody_design_manager | 5.0.0 |
| ibm | rational_software_architect_design_manager | 5.0.2 |
| ibm | rational_software_architect_design_manager | 6.0.0 |
| ibm | rational_rhapsody_design_manager | 6.0.3 |
| ibm | rational_software_architect_design_manager | 5.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.4 |
| ibm | rational_software_architect_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.5 |
| ibm | rational_rhapsody_design_manager | 6.0.1 |
| ibm | rational_rhapsody_design_manager | 6.0.2 |
| ibm | rational_rhapsody_design_manager | 5.0.2 |
| ibm | rational_rhapsody_design_manager | 6.0.0 |
An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_requirements_management_doors | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used to execute commands as root. IBM X-Force ID: 140211.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | puredata_system_for_analytics | 1.0.0 |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140362.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a denial of service. IBM X-Force ID: 140363.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H | 2.8 | 4.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account credentials. IBM X-Force ID: 140368.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force ID: 140395.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM X-Force ID: 140396.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.6 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 140397.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.6 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v5000_firmware | * |
| ibm | storwize_v7000_firmware | * |
| ibm | san_volume_controller_firmware | * |
| ibm | storwize_v3700_firmware | * |
| ibm | storwize_v3500_firmware | * |
| ibm | spectrum_virtualize | * |
| ibm | spectrum_virtualize_for_public_cloud | * |
| ibm | storwize_v9000_firmware | * |
The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_unified_v7000_software | 1.6 |
IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details to which they are not authorized. IBM X-Force ID: 140399.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | 5.0.8.1 |
| ibm | api_connect | 5.0.8.2 |
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_file_gateway | * |
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-307,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 140757.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 140760.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user session. IBM X-Force ID: 140762.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 9.0 |
| ibm | websphere_portal | 8.5.0.0 |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 140969.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 140970.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141097.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 5.0.2 |
| ibm | rational_doors_next_generation | 6.0.5 |
| ibm | rational_doors_next_generation | 6.0.3 |
| ibm | rational_doors_next_generation | 6.0.2 |
| ibm | rational_doors_next_generation | 6.0.0 |
| ibm | rational_doors_next_generation | 5.0 |
| ibm | rational_doors_next_generation | 5.0.1 |
| ibm | rational_doors_next_generation | 6.0.4 |
| ibm | rational_doors_next_generation | 6.0.1 |
IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flashsystem_840_firmware | - |
| ibm | flashsystem_900_firmware | - |
IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.1 |
| ibm | content_navigator | 3.0.0 |
| ibm | content_navigator | 3.0.2 |
| ibm | content_navigator | 3.0.3 |
| ibm | content_navigator | 2.0.3 |
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.
CVSS 2.0
Severity: LOW
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.5 |
IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141338.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_manager | 8.5 |
| ibm | content_manager | 8.4.3 |
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 141340.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i2_enterprise_insight_analysis | 2.1.7 |
| ibm | i2_enterprise_insight_analysis | 2.1.8 |
IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i2_enterprise_insight_analysis | 2.1.7 |
| ibm | i2_enterprise_insight_analysis | 2.1.8 |
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | 6.0.5 |
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 141417.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | 10.5 |
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141551.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 141622.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10.0 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | satellite | 5.6 |
| ibm | software_development_kit | 8.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| ibm | software_development_kit | 6 |
| ibm | software_development_kit | 6.0 |
| redhat | satellite | 5.7 |
| ibm | software_development_kit | 6r1 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| ibm | software_development_kit | 7 |
| redhat | satellite | 5.8 |
| ibm | software_development_kit | 8 |
| ibm | software_development_kit | 7r1 |
| ibm | software_development_kit | 7.0 |
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
CVSS 2.0
Severity: LOW
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_server | 11.7 |
IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141802.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141803.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141804.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-1188,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_transportation | 7.6.1.0 |
| ibm | maximo_for_transportation | 7.6.2.1 |
| ibm | maximo_for_utilities | 7.6.0.0 |
| ibm | maximo_for_nuclear_power | 7.6.0.0 |
| ibm | smartcloud_control_desk | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.3.0 |
| ibm | maximo_asset_management | * |
| ibm | maximo_for_aviation | 7.6.1.0 |
| ibm | maximo_for_oil_and_gas | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.2.0 |
| ibm | maximo_for_transportation | 7.6.2.3 |
| ibm | maximo_for_transportation | 7.6.2.0 |
| ibm | maximo_for_transportation | 7.6.2.4 |
| ibm | maximo_for_life_sciences | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.0.0 |
| ibm | smartcloud_control_desk | 7.6.0.1 |
| ibm | maximo_for_oil_and_gas | 7.5.0.0 |
| ibm | maximo_for_aviation | 7.6.2.1 |
| ibm | maximo_for_transportation | 7.6.2.2 |
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142117.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i2_enterprise_insight_analysis | 2.1.7 |
| ibm | i2_enterprise_insight_analysis | 2.1.8 |
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_for_transportation | 7.6.1.0 |
| ibm | maximo_for_transportation | 7.6.2.1 |
| ibm | maximo_for_utilities | 7.6.0.0 |
| ibm | maximo_for_nuclear_power | 7.6.0.0 |
| ibm | smartcloud_control_desk | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.3.0 |
| ibm | maximo_asset_management | * |
| ibm | maximo_for_aviation | 7.6.1.0 |
| ibm | maximo_for_oil_and_gas | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.2.0 |
| ibm | maximo_for_transportation | 7.6.2.3 |
| ibm | maximo_for_transportation | 7.6.2.0 |
| ibm | maximo_for_transportation | 7.6.2.4 |
| ibm | maximo_for_life_sciences | 7.6.0.0 |
| ibm | maximo_for_aviation | 7.6.0.0 |
| ibm | smartcloud_control_desk | 7.6.0.1 |
| ibm | maximo_for_aviation | 7.6.2.1 |
| ibm | maximo_for_transportation | 7.6.2.2 |
IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142291.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_requirements_composer | * |
| ibm | rational_doors_next_generation | * |
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.6 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.5 |
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.6 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.5 |
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124557.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142558.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0.0.9 |
| ibm | websphere_commerce | * |
IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 142597.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 5.2.1 |
| ibm | content_foundation | 5.2.1 |
| ibm | content_foundation | 5.5.0 |
| ibm | filenet_content_manager | 5.5.0 |
IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142598.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | 9.0 |
| ibm | websphere_mq | 8.0 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 142648.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_client | * |
| ibm | spectrum_protect_for_virtual_environments | * |
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142650.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| psirt@us.ibm.com | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.2 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10.0 |
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696.
CVSS 2.0
Severity: LOW
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_storage_manager | * |
| ibm | tivoli_storage_manager_for_virtual_environments | * |
| ibm | tivoli_storage_manager_for_space_management | * |
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10 |
| ibm | robotic_process_automation_with_automation_anywhere | 11 |
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142891.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | * |
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142892.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 5.2.1 |
| ibm | content_foundation | 5.2.1 |
| ibm | content_foundation | 5.5.0 |
| ibm | filenet_content_manager | 5.5.0 |
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142893.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 5.2.1 |
| ibm | content_foundation | 5.2.1 |
| ibm | content_foundation | 5.5.0 |
| ibm | filenet_content_manager | 5.5.0 |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142955.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142956.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142958.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142967.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
| ibm | sterling_file_gateway | * |
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-134,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 143121.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | * |
IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to access and manipulate documents on StoredIQ managed data sources. IBM X-Force ID: 143331.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storediq | 7.6.0 |
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143497.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143498.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about the application and database that could be used to conduct further attacks. IBM X-Force ID: 143500.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_software_architect_design_manager | * |
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143501.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checksums. IBM X-Force ID: 143568.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | multi-cloud_data_encryption | * |
IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 7.1.1 |
| ibm | spectrum_symphony | 7.1.2 |
| ibm | spectrum_symphony | 7.2.0.2 |
| ibm | platform_symphony | 6.1.1 |
| ibm | platform_symphony | 7.1.0 |
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143791.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143792.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143793.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143794.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143795.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system. IBM X-Force ID: 143796.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143797.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143931.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | 7.3.0 |
| ibm | qradar_security_information_and_event_manager | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144343.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
CVSS 2.0
Severity: LOW
Problem Type: CWE-312,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.0.0.0 |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 144410.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | * |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 144580.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | 7.0 |
| ibm | websphere_commerce | * |
IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated user to cause a denial of service. IBM X-Force ID: 144650.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-770,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
CVSS 2.0
Severity: LOW
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq_appliance | * |
| ibm | datapower_gateway | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144726.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 144747.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | * |
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 7.2 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | satellite | 5.6 |
| redhat | enterprise_linux_server | 7.0 |
| oracle | enterprise_manager_base_platform | 13.2.0.0.0 |
| ibm | sdk | 7.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| ibm | sdk | 6.0 |
| ibm | sdk | 8.0 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| oracle | enterprise_manager_base_platform | 13.3.0.0.0 |
| redhat | satellite | 5.8 |
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144883.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 2.1.2 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.6 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.5 |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 144884.
CVSS 2.0
Severity: LOW
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144885.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | 2018.4 |
| ibm | datapower_gateway | * |
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
| ibm | datapower_gateway | 2018.4.1.0 |
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144893.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 144950.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.2.1 |
IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-force ID: 144951.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | 7.0.3.0 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_automation_workflow | 18.0.0.0 |
| ibm | business_automation_workflow | 18.0.0.1 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | * |
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are configured to use TADDM. IBM X-Force ID: 145110.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | * |
IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145118.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | planning_analytics_local | * |
IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 145171.
CVSS 2.0
Severity: LOW
Problem Type: CWE-755,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | * |
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_privileged_identity_manager | 2.1.1 |
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-311,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of service attack. IBM X-Force ID: 145456.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
| ibm | websphere_mq | 9.1.0.0 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145505.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | * |
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145510.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rhapsody_model_manager | 6.0.6 |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145582.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145583.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 145609.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-290,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 7.0.0.0 |
| ibm | websphere_application_server | 8.0.0.0 |
IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | * |
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145968.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | * |
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_server | 11.7 |
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 7.1.1 |
| ibm | platform_symphony | 7.1 |
| ibm | spectrum_symphony | 7.1.2 |
| ibm | spectrum_symphony | 7.2.0.2 |
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 146339.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 7.1.1 |
| ibm | platform_symphony | 7.1 |
| ibm | spectrum_symphony | 7.1.2 |
| ibm | spectrum_symphony | 7.2.0.2 |
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 7.1.1 |
| ibm | platform_symphony | 7.1 |
| ibm | spectrum_symphony | 7.1.2 |
| ibm | spectrum_symphony | 7.2.0.2 |
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_symphony | 7.2.0.2 |
IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | platform_symphony | 7.1.1 |
| ibm | platform_symphony | 7.1 |
| ibm | specturm_symphony | 7.2.0.2 |
| ibm | specturm_symphony | 7.1.2 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | * |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147166.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | 9.0.4.0 |
| ibm | security_access_manager | 9.0.5.0 |
IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | * |
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_lsf | 9.1.1 |
| ibm | spectrum_lsf | 9.1.2 |
| ibm | spectrum_lsf | 10.1 |
| ibm | spectrum_lsf | 9.1.3 |
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server | 9.1 |
| ibm | infosphere_information_server | 11.7 |
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_incident_forensics | * |
| ibm | qradar_incident_forensics | 7.2.8 |
| ibm | qradar_incident_forensics | 7.3.1 |
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147709.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | * |
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147710.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | doors_next_generation | * |
IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_advisor_with_watson | * |
IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.8 |
| ibm | qradar_security_information_and_event_manager | 7.3.1 |
| ibm | qradar_security_information_and_event_manager | * |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 147906.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 7.0.0.2 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 7.0.0.1 |
| ibm | websphere_portal | 7.0.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148419.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 148421.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 148422.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148423.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 148511.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | 3.0.0.1 |
| ibm | security_key_lifecycle_manager | 3.0 |
| ibm | security_key_lifecycle_manager | * |
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_key_lifecycle_manager | * |
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.4 |
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | 5.2.3.2 |
| ibm | security_identity_governance_and_intelligence | 5.2.4 |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148613.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148615.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148617.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148618.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148620.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_plus | 10.1.1 |
| ibm | spectrum_protect_plus | 10.1.0 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | domino | 9.0.0.0 |
| ibm | domino | 9.0.1.10 |
| ibm | domino | * |
| ibm | notes | 9.0.1.10 |
| ibm | notes | 9.0.0.0 |
| ibm | notes | * |
IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148689.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spss_analytic_server | 3.1.1.1 |
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | datacap | 9.1.1 |
| ibm | datacap | 9.1.4 |
| ibm | datacap | 9.1.3 |
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-1236,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_virtualize_software_for_public_cloud | * |
| ibm | spectrum_virtualize_software | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-770,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | 5.0.1.0 |
| ibm | spectrum_scale | 5.0.1.1 |
IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | * |
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_client | * |
| ibm | spectrum_protect_for_virtual_environments | * |
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect | * |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_hyper-v | * |
| ibm | tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware | * |
| ibm | tivoli_storage_manager | * |
| ibm | spectrum_protect_manager_for_virtual_environments_data_protection_for_vmware | * |
| ibm | spectrum_protect_for_virtual_environments_data_protection_for_hyper-v | * |
IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect_server | * |
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-918,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an attacker could exploit this vulnerability to induce the Connections server to attack other systems. IBM X-Force ID: 148946.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 5.5 |
| ibm | connections | 6.0 |
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
| ibm | websphere_mq | 9.1.0.0 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0 |
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 8.0 |
| ibm | websphere_application_server | 8.5 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148949.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149073.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10.0 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
| ibm | sterling_b2b_integrator | 6.2.6.1 |
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_message_broker | * |
| ibm | app_connect | * |
| ibm | integration_bus | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 149702.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-1021,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 149703.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 149704.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_commerce | * |
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the security context of the hosting Web site, once victim opens a certain page in Control Room. IBM X-Force ID: 149883.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 10.0 |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 150018.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150019.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150021.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.6.0 |
| ibm | financial_transaction_manager | 3.1.0.2 |
| ibm | financial_transaction_manager | 3.0.6.1 |
| ibm | financial_transaction_manager | 3.0.4.0 |
| ibm | financial_transaction_manager | 3.0.2.1 |
| ibm | financial_transaction_manager | 3.1.0.1 |
| ibm | financial_transaction_manager | 3.2.0.0 |
| ibm | financial_transaction_manager | 3.1.0.0 |
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_portal | 8.0.0.1 |
| ibm | websphere_portal | 8.0.0.0 |
| ibm | websphere_portal | 8.5.0.0 |
| ibm | websphere_portal | 9.0.0.0 |
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | qlogic_4_gb_fibre_channel_expansion_card_firmware | 5.5.2.6.0 |
| ibm | qlogic_20-port_4/8_gb_san_switch_module_firmware | 7.10.1.20.0 |
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150170.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | operational_decision_manager | * |
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | flashsystem_900_firmware | 1.4 |
| ibm | flashsystem_840_firmware | 1.4 |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150426.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150427.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150428.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150432.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | event_streams | 2018.3.0 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-59,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150514.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | daeja_viewone | 5.0 |
IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150661.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq | * |
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 9.0.0.0 |
| ibm | websphere_application_server | * |
| ibm | websphere_application_server | 8.5.0.0 |
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-668,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_private | 2.1.0 |
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
CVSS 2.0
Severity: LOW
Problem Type: CWE-347,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| netapp | oncommand_insight | - |
| ibm | cognos_analytics | * |
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_private | 3.1.0 |
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | filenet_content_manager | 5.2.1 |
| ibm | filenet_content_manager | 5.5.0 |
IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150945.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | business_process_manager | 8.5.6.0 |
| ibm | business_process_manager | 8.5.5.0 |
| ibm | business_automation_workflow | 18.0.0.0 |
| ibm | business_automation_workflow | 18.0.0.1 |
| ibm | business_process_manager | 8.5.7.0 |
| ibm | business_process_manager | 8.6.0.0 |
| ibm | business_process_manager | * |
| ibm | websphere | * |
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | 9.0.3.1 |
| ibm | security_access_manager | 9.0.4.0 |
| ibm | security_access_manager | 9.0.5.0 |
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 11.1 |
IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.0.5.0 |
| ibm | financial_transaction_manager | 3.0.2.0 |
| ibm | financial_transaction_manager | 3.0.5.1 |
| ibm | financial_transaction_manager | 3.0.0.0 |
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151330.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | maximo_asset_management | 7.6 |
IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 151639.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_governance_catalog | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.3 |
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.5 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 11.0 |
IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.
CVSS 2.0
Severity: LOW
Problem Type: CWE-312,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 11.0 |
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | 11 |
A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into the MQ Console REST API. IBM X-Force ID: 151969.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | mq | 9.1.0.0 |
| ibm | mq | * |
IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques. IBM X-Force ID: 151970.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | case_manager | 5.3.3.0 |
| ibm | case_manager | 5.2.1.0 |
| ibm | case_manager | 5.2.1.7 |
| ibm | case_manager | 5.2.0.4 |
| ibm | case_manager | 5.2.0.0 |
| ibm | case_manager | 5.3.0.0 |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 152078.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i_access | * |
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-427,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sdk | 8.0 |
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_guardium | * |
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_governance_catalog | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.3 |
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.5 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.
CVSS 2.0
Severity: LOW
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 5.5 |
| ibm | connections | 6.0 |
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_governance_catalog | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.3 |
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_governance_catalog | 11.5 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | curam_social_program_management | * |
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
| ibm | infosphere_information_server | 11.7 |
IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152734.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152736.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_doors_next_generation | * |
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152737.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | doors_next_generation | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152738.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_information_server | 11.3 |
| ibm | infosphere_information_server | 11.5 |
| ibm | infosphere_information_server_on_cloud | 11.7 |
| ibm | infosphere_information_server_on_cloud | 11.5 |
| ibm | infosphere_information_server | 11.7 |
IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152785.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | jazz_reporting_service | * |
IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152855.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | marketing_platform | 10.1 |
| ibm | marketing_platform | 9.1.2 |
| ibm | marketing_platform | 9.1.0 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storediq | * |
IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | storediq | * |
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_engineering_lifecycle_manager | * |
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | connections | 5.0 |
| ibm | connections | 5.5 |
| ibm | connections | 6.0 |
IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 11.1.2.2 |
| ibm | db2 | 11.1.3.3 |
| ibm | db2 | 11.1.4.4 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 10.1.0.6 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.0 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.5.0.9 |
| ibm | db2 | 10.5.0.8 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2 | 10.5.0.10 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 11.1.1.1 |
| ibm | db2 | 10.1.0.0 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 10.5.0.0 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2 | 10.5.0.6 |
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.
CVSS 2.0
Severity: LOW
Problem Type: CWE-311,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_private | 3.1.1 |
IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.
CVSS 2.0
Severity: LOW
Problem Type: CWE-311,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_private | 3.1.1 |
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 153319.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | cloud_private | 3.1.1 |
IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | campaign | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153386.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 153387.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153427.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 153428.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks against the system. IBM X-Force ID: 153430.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_governance_and_intelligence | * |
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | engineering_lifecycle_optimization_-_publishing | 2.1.2 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.6 |
| ibm | engineering_lifecycle_optimization_-_publishing | 6.0.5 |
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153495.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_quality_manager | * |
| ibm | rational_engineering_lifecycle_manager | * |
| ibm | rational_rhapsody_design_manager | * |
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_software_architect_design_manager | * |
| ibm | rational_doors_next_generation | * |
| ibm | rational_team_concert | * |
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153633.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.
CVSS 2.0
Severity: LOW
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153748.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_access_manager | * |
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileges when using multiplexed channels. IBM X-Force ID: 153915.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 11.1 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154135.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154136.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_collaborative_lifecycle_management | * |
| ibm | rational_team_concert | * |
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154137.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_team_concert | * |
The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | power_system_s914_(9009-41a)_firmware | * |
| ibm | power_system_s924_(9009-42a)_firmware | * |
| ibm | power_system_lc921_(9006-12p)_firmware | * |
| ibm | power_system_h922_(9223-22h)_firmware | * |
| ibm | power_system_h924_(9223-42h)_firmware | * |
| ibm | power_system_l922_(9008-22l)_firmware | * |
| ibm | power_system_ac922_(8335-gth)_firmware | * |
| ibm | power_system_lc922_(9006-22p)_firmware | * |
| ibm | power_system_s922_(9009-22a)_firmware | * |
| ibm | power_system_ac922_(8335-gtg)_firmware | * |
| ibm | power_system_ac922_(8335-gtx)_firmware | * |
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_scale | * |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650.
CVSS 2.0
Severity: LOW
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM X-ForceID: 154887.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_mq | * |
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | robotic_process_automation_with_automation_anywhere | * |
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 155265.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | 6.0.0.2 |
| ibm | security_identity_manager | 6.0.0 |
| ibm | security_identity_manager | 6.0.0.20 |
| ibm | security_identity_manager | 6.0.0.5 |
| ibm | security_identity_manager | 6.0.0.6 |
| ibm | security_identity_manager | 6.0.0.18 |
| ibm | security_identity_manager | 6.0.0.1 |
| ibm | security_identity_manager | 6.0.0.4 |
| ibm | security_identity_manager | 6.0.0.10 |
| ibm | security_identity_manager | 6.0.0.0 |
| ibm | security_identity_manager | 6.0.0.3 |
| ibm | security_identity_manager | 6.0.0.19 |
| ibm | security_identity_manager | 6.0.0.14 |
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 3.2.1.0 |
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lenovo | flex_system_x480_x6_firmware | * |
| lenovo | flex_system_x880_firmware | * |
| lenovo | system_x3950_x6_firmware | * |
| ibm | system_x3250_m4_firmware | * |
| lenovo | system_x3750_m4_firmware | * |
| ibm | system_x3500_m4_firmware | * |
| ibm | system_x3550_m4_firmware | * |
| ibm | bladecenter_hs22_firmware | * |
| lenovo | flex_system_x240_m5_firmware | * |
| lenovo | system_x3500_m5_firmware | * |
| ibm | nextscale_nx360_m4_firmware | * |
| ibm | system_x3950_x6_firmware | * |
| lenovo | system_x3250_m6_firmware | * |
| ibm | system_x3650_m4_bd_firmware | * |
| lenovo | system_x3550_m5_firmware | * |
| ibm | system_x3650_m4_firmware | * |
| lenovo | nextscale_nx360_m5_firmware | * |
| ibm | flex_system_x280_m4_firmware | * |
| ibm | flex_system_x880_m4_firmware | * |
| ibm | system_x3650_m4_hd_firmware | * |
| ibm | system_x3750_m4_firmware | * |
| ibm | system_x3530_m4_firmware | * |
| lenovo | flex_system_x440_m4_firmware | * |
| ibm | flex_system_x480_m4_firmware | * |
| ibm | system_x3100_m4_firmware | * |
| ibm | system_x3630_m4_firmware | * |
| lenovo | system_x3650_m5_firmware | * |
| ibm | idataplex_dx360_m4_firmware | * |
| ibm | system_x3250_m5_firmware | * |
| ibm | flex_system_x220_m4_firmware | * |
| lenovo | system_x3850_x6_firmware | * |
| lenovo | flex_system_x280_x6_firmware | * |
| ibm | flex_system_x440_m4_firmware | * |
| ibm | flex_system_x222_m4_firmware | * |
| lenovo | flex_system_x240_m4_firmware | * |
| ibm | flex_system_x240_m4_firmware | * |
| ibm | bladecenter_hs23e_firmware | * |
| ibm | system_x3100_m5_firmware | * |
| ibm | idataplex_dx360_m4_water_cooled_firmware | * |
| ibm | system_x3850_x6_firmware | * |
| ibm | system_x3300_m4_firmware | * |
| ibm | bladecenter_hs23_firmware | * |
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-276,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | system_x3250_m4_firmware | * |
| lenovo | system_x3750_m4_firmware | * |
| ibm | system_x3500_m4_firmware | * |
| ibm | system_x3550_m4_firmware | * |
| ibm | system_x3950_x6_firmware | * |
| ibm | flex_system_x480_x6_firmware | * |
| ibm | system_x3650_m4_bd_firmware | * |
| ibm | system_x3650_m4_firmware | * |
| ibm | system_x3650_m4_hd_firmware | * |
| ibm | system_x3750_m4_firmware | * |
| ibm | system_x3530_m4_firmware | * |
| lenovo | flex_system_x440_m4_firmware | * |
| ibm | system_x3100_m4_firmware | * |
| ibm | system_x3630_m4_firmware | * |
| ibm | flex_system_x880_x6_firmware | * |
| ibm | idataplex_dx360_m4_firmware | * |
| ibm | system_x3250_m5_firmware | * |
| ibm | flex_system_x220_m4_firmware | * |
| ibm | flex_system_x280_x6_firmware | * |
| ibm | flex_system_x440_m4_firmware | * |
| ibm | flex_system_x222_m4_firmware | * |
| lenovo | flex_system_x240_m4_firmware | * |
| ibm | flex_system_x240_m4_firmware | * |
| ibm | bladecenter_hs23e_firmware | * |
| ibm | system_x3100_m5_firmware | * |
| ibm | idataplex_dx360_m4_water_cooled_firmware | * |
| ibm | system_x3850_x6_firmware | * |
| ibm | system_x3300_m4_firmware | * |
| ibm | bladecenter_hs23_firmware | * |
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 11.1.2.2 |
| ibm | db2 | 11.1.3.3 |
| ibm | db2 | 11.1.4.4 |
| ibm | db2 | 9.7.0.9 |
| ibm | db2 | 10.1.0.1 |
| ibm | db2 | 10.1.0.6 |
| ibm | db2 | 9.7.0.5 |
| ibm | db2 | 9.7.0.0 |
| ibm | db2 | 9.7.0.6 |
| ibm | db2 | 9.7.0.10 |
| ibm | db2 | 11.1.0.0 |
| ibm | db2 | 9.7.0.8 |
| ibm | db2 | 10.5.0.1 |
| ibm | db2 | 10.1.0.4 |
| ibm | db2 | 10.5.0.9 |
| ibm | db2 | 10.5.0.8 |
| ibm | db2 | 10.5.0.2 |
| ibm | db2 | 9.7.0.2 |
| ibm | db2 | 9.7.0.1 |
| ibm | db2 | 10.1.0.5 |
| ibm | db2 | 10.5.0.10 |
| ibm | db2 | 10.1.0.2 |
| ibm | db2 | 10.5.0.4 |
| ibm | db2 | 11.1.1.1 |
| ibm | db2 | 10.1.0.0 |
| ibm | db2 | 10.1.0.3 |
| ibm | db2 | 10.5.0.7 |
| ibm | db2 | 9.7.0.4 |
| ibm | db2 | 9.7.0.7 |
| ibm | db2 | 10.5.0.0 |
| ibm | db2 | 9.7.0.3 |
| ibm | db2 | 10.5.0.5 |
| ibm | db2 | 10.5.0.3 |
| ibm | db2 | 9.7.0.11 |
| ibm | db2 | 10.5.0.6 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-120,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 155905.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155906.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 155907.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
| ibm | websphere_virtual_enterprise | 7.0 |
| ibm | websphere_virtual_enterprise | 8.0 |
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-ForceID: 155998.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | * |
IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be executed on the user's workstation. IBM X-Force ID: 156000.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.0 |
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.0 |
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.2 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.3 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | security_identity_manager | * |
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2.8 | 2.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | i | 7.2 |
| ibm | i | 7.3 |
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 156239.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L | 2.8 | 4.2 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
| ibm | sterling_b2b_integrator | 6.0.0.0 |
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | api_connect | * |
IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | rational_clearcase | * |
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 3.9 | 1.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | bigfix_platform | * |
IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this information using man in the middle techniques. IBM X-ForceID: 157008.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.2 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-319,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | sterling_b2b_integrator | * |
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | * |
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 4.4 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N | 1.8 | 2.5 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | spectrum_protect | 8.1.7 |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-427,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| ibm | db2 | 10.5 |
| ibm | db2 | 11.1 |
| ibm | db2 | 10.1 |
| ibm | db2 | 9.7 |