ibm

8,321 tracked vulnerabilities.

CVE-2018-1560 MEDIUM
IBM Rational Engineering Lifecycle Manager 5.0-5.02 and 6.0-6.0.6 - Cross-Site Scripting
Sep 25, 2018
CVSS 5.4
EPSS 0.01
CVE-2018-1539 MEDIUM
IBM Rational Engineering Lifecycle Manager 5.0-5.02 and 6.0-6.0.6 - Authentication Bypass via Direct Request
Sep 25, 2018
CVSS 5.4
EPSS 0.01
CVE-2018-1711 HIGH
IBM DB2 9.7, 10.1, 10.5, 11.1 - Privilege Escalation via Task Column Modification
Sep 21, 2018
CVSS 8.4
EPSS 0.00
CVE-2018-1710 HIGH
IBM DB2 10.1, 10.5, 11.1 - Buffer Overflow in db2licm
Sep 21, 2018
CVSS 8.4
EPSS 0.01
CVE-2018-1685 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.1 - Unauthorized File Read via db2cacpy
Sep 21, 2018
CVSS 5.5
EPSS 0.00
CVE-2018-1800 MEDIUM
IBM Sterling B2B Integrator 5.2.6.0 and 6.2.6.1 - Exposure of Sensitive Information During Installation
Sep 20, 2018
CVSS 5.1
EPSS 0.00
CVE-2018-1674 MEDIUM
IBM Business Process Manager <18.0.0.1 - SQL Injection
Sep 20, 2018
CVSS 6.3
EPSS 0.02
CVE-2018-1782 MEDIUM
IBM Spectrum Scale <5.0.1.2 - Memory Corruption
Sep 19, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-1791 MEDIUM
IBM Connections 5.0, 5.5, and 6.0 - External Service Interaction via Request Property
Sep 14, 2018
CVSS 4.9
EPSS 0.01
CVE-2018-1719 MEDIUM
IBM WebSphere Application Server <9.0 - SSL Downgrade
Sep 14, 2018
CVSS 5.9
EPSS 0.02
CVE-2018-1698 MEDIUM
IBM Maximo Asset Mgmt <7.6.3 - Info Disclosure
Sep 13, 2018
CVSS 5.3
EPSS 0.02
CVE-2018-1773 MEDIUM
IBM Datacap 9.1.1, 9.1.3, 9.1.4 - Authenticated Authentication Bypass
Sep 12, 2018
CVSS 4.3
EPSS 0.01
CVE-2018-1571 HIGH
IBM QRadar 7.2-7.3 - Command Injection
Sep 11, 2018
CVSS 8.8
EPSS 0.05
CVE-2018-1789 HIGH
IBM API Connect 2018.1.0-2018.3.4 - Server-Side Request Forgery
Sep 07, 2018
CVSS 8.4
EPSS 0.01
CVE-2018-1757 MEDIUM
IBM Security Identity Governance and Intelligence 5.2.3.2/5.2.4 - Sensitive Information Exposure
Sep 07, 2018
CVSS 5.3
EPSS 0.02
CVE-2018-1756 HIGH
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 - SQL Injection
Sep 07, 2018
CVSS 7.5
EPSS 0.11
CVE-2018-1567 CRITICAL
IBM WebSphere Application Server 7.0.0.0-7.0.0.44 - Remote Code Execution via SOAP Connector Deserialization
Sep 07, 2018
CVSS 9.8
EPSS 0.04
CVE-2018-1695 HIGH
IBM WebSphere App Server <8.5.5 - CSRF
Sep 06, 2018
CVSS 7.3
EPSS 0.02
CVE-2018-1705 MEDIUM
IBM Platform Symphony 7.1, 7.1.1 & IBM Spectrum Symphony 7.1.2, 7.2.0.2 - Sensitive Info Exposure
Aug 28, 2018
CVSS 6.5
EPSS 0.01
CVE-2018-1644 LOW
IBM WebSphere Commerce 7.0.0.0-9.0.0.4 - Authenticated Exposure of Sensitive Information
Aug 27, 2018
CVSS 3.1
EPSS 0.01
CVE-2018-1755 MEDIUM
IBM WebSphere Application Server Liberty - Sensitive Information Exposure via JASPIC Authentication
Aug 24, 2018
CVSS 5.9
EPSS 0.03
CVE-2018-1722 CRITICAL
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 - Remote Code Execution
Aug 24, 2018
CVSS 10.0
EPSS 0.09
CVE-2018-1699 MEDIUM
IBM Maximo Asset Management <7.6.3 - SQL Injection
Aug 24, 2018
CVSS 6.3
EPSS 0.02
CVE-2018-1599 MEDIUM
IBM API Connect 5.0.0.0-5.0.8.3 - Clickjacking via Malicious Website
Aug 22, 2018
CVSS 5.4
EPSS 0.01
CVE-2018-1656 HIGH
IBM SDK Java Technology Edition 6.0, 7.0, 8.0 - Path Traversal in Diagnostic Tooling Framework
Aug 20, 2018
CVSS 7.4
EPSS 0.05