ibm

8,321 tracked vulnerabilities.

CVE-2017-1577 HIGH
IBM WebSphere Portal 7.0, 8.0, 8.5, 9.0 - Path Traversal via Dot Dot Sequences
Sep 28, 2017
CVSS 7.5
EPSS 0.03
CVE-2017-1483 HIGH
IBM Security Identity Manager 6.0-7.0 - Unauthenticated Critical Function Access
Sep 28, 2017
CVSS 8.6
EPSS 0.01
CVE-2017-1407 HIGH
IBM Security Identity Manager 6.0-7.0 - Authenticated Remote Command Execution
Sep 28, 2017
CVSS 8.8
EPSS 0.03
CVE-2017-1539 HIGH
IBM Business Process Manager 7.5, 8.0, 8.5 - Privilege Escalation via LDAP Group Membership Manipulation
Sep 26, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-1531 MEDIUM
IBM Business Process Manager 7.5, 8.0, 8.5 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1530 MEDIUM
IBM Business Process Manager 7.5, 8.0, 8.5 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1527 HIGH
IBM Business Process Manager 7.5, 8.0, and 8.5 - XML External Entity Injection
Sep 26, 2017
CVSS 8.1
EPSS 0.02
CVE-2017-1425 MEDIUM
IBM Business Process Manager 8.0.1.1 and 8.5.7 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1555 MEDIUM
IBM API Connect 5.0.0.0-5.0.7.2 - Authenticated API Token Generation Bypass
Sep 25, 2017
CVSS 4.3
EPSS 0.01
CVE-2017-1551 MEDIUM
IBM API Connect - Improper Input Validation
Sep 25, 2017
CVSS 6.1
EPSS 0.01
CVE-2017-1424 MEDIUM
IBM Business Process Manager 8.5.7 - Stored Cross-Site Scripting
Sep 25, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1362 HIGH
IBM Security Identity Manager Adapters <7.0 - Info Disclosure
Sep 25, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1346 LOW
IBM Business Process Manager <8.6 - Info Disclosure
Sep 25, 2017
CVSS 2.5
EPSS 0.00
CVE-2017-1235 MEDIUM
IBM WebSphere MQ 8.0 - Authenticated Denial of Service
Sep 25, 2017
CVSS 6.5
EPSS 0.02
CVE-2017-1490 MEDIUM
IBM Jazz Reporting Service 6.0-6.0.4 - Exposure of Sensitive Information in Lifecycle Query Engine
Sep 14, 2017
CVSS 5.3
EPSS 0.01
CVE-2017-1556 MEDIUM
IBM API Connect 5.0.7.0-5.0.7.2 - Authenticated Denial of Service via Regular Expression Attack
Sep 13, 2017
CVSS 6.5
EPSS 0.01
CVE-2017-1508 MEDIUM
IBM Informix Dynamic Server 12.1 - Privilege Escalation
Sep 13, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1520 LOW
IBM DB2 9.7, 10.1, 10.5, and 11.1 - Improper Authentication
Sep 12, 2017
CVSS 3.7
EPSS 0.01
CVE-2017-1519 MEDIUM
IBM DB2 10.5-11.1 - Denial of Service
Sep 12, 2017
CVSS 5.9
EPSS 0.02
CVE-2017-1452 HIGH
IBM DB2 9.7-11.1 - Privilege Escalation and Arbitrary File Write
Sep 12, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1451 HIGH
IBM DB2 9.7-11.1 - Privilege Escalation to Root via DB2 Instance Owner
Sep 12, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1439 MEDIUM
IBM DB2 9.7-11.1 - Privilege Escalation to Root via DB2 Instance Owner
Sep 12, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1438 MEDIUM
IBM DB2 9.7-11.1 - Privilege Escalation to Root
Sep 12, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1434 MEDIUM
IBM DB2 11.1 - Exposure of Sensitive Information in Error Log
Sep 12, 2017
CVSS 4.7
EPSS 0.00
CVE-2017-1352 MEDIUM
IBM Maximo Asset Mgmt <7.6 - Command Injection
Sep 12, 2017
CVSS 5.5
EPSS 0.01