ibm
8,321 tracked vulnerabilities.
CVE-2017-1577
HIGH
IBM WebSphere Portal 7.0, 8.0, 8.5, 9.0 - Path Traversal via Dot Dot Sequences
Sep 28, 2017
CVSS 7.5
EPSS 0.03
CVE-2017-1483
HIGH
IBM Security Identity Manager 6.0-7.0 - Unauthenticated Critical Function Access
Sep 28, 2017
CVSS 8.6
EPSS 0.01
CVE-2017-1407
HIGH
IBM Security Identity Manager 6.0-7.0 - Authenticated Remote Command Execution
Sep 28, 2017
CVSS 8.8
EPSS 0.03
CVE-2017-1539
HIGH
IBM Business Process Manager 7.5, 8.0, 8.5 - Privilege Escalation via LDAP Group Membership Manipulation
Sep 26, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-1531
MEDIUM
IBM Business Process Manager 7.5, 8.0, 8.5 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1530
MEDIUM
IBM Business Process Manager 7.5, 8.0, 8.5 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1527
HIGH
IBM Business Process Manager 7.5, 8.0, and 8.5 - XML External Entity Injection
Sep 26, 2017
CVSS 8.1
EPSS 0.02
CVE-2017-1425
MEDIUM
IBM Business Process Manager 8.0.1.1 and 8.5.7 - Cross-Site Scripting
Sep 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1555
MEDIUM
IBM API Connect 5.0.0.0-5.0.7.2 - Authenticated API Token Generation Bypass
Sep 25, 2017
CVSS 4.3
EPSS 0.01
CVE-2017-1551
MEDIUM
IBM API Connect - Improper Input Validation
Sep 25, 2017
CVSS 6.1
EPSS 0.01
CVE-2017-1424
MEDIUM
IBM Business Process Manager 8.5.7 - Stored Cross-Site Scripting
Sep 25, 2017
CVSS 5.4
EPSS 0.01
CVE-2017-1362
HIGH
IBM Security Identity Manager Adapters <7.0 - Info Disclosure
Sep 25, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1346
LOW
IBM Business Process Manager <8.6 - Info Disclosure
Sep 25, 2017
CVSS 2.5
EPSS 0.00
CVE-2017-1235
MEDIUM
IBM WebSphere MQ 8.0 - Authenticated Denial of Service
Sep 25, 2017
CVSS 6.5
EPSS 0.02
CVE-2017-1490
MEDIUM
IBM Jazz Reporting Service 6.0-6.0.4 - Exposure of Sensitive Information in Lifecycle Query Engine
Sep 14, 2017
CVSS 5.3
EPSS 0.01
CVE-2017-1556
MEDIUM
IBM API Connect 5.0.7.0-5.0.7.2 - Authenticated Denial of Service via Regular Expression Attack
Sep 13, 2017
CVSS 6.5
EPSS 0.01
CVE-2017-1508
MEDIUM
IBM Informix Dynamic Server 12.1 - Privilege Escalation
Sep 13, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1520
LOW
IBM DB2 9.7, 10.1, 10.5, and 11.1 - Improper Authentication
Sep 12, 2017
CVSS 3.7
EPSS 0.01
CVE-2017-1519
MEDIUM
IBM DB2 10.5-11.1 - Denial of Service
Sep 12, 2017
CVSS 5.9
EPSS 0.02
CVE-2017-1452
HIGH
IBM DB2 9.7-11.1 - Privilege Escalation and Arbitrary File Write
Sep 12, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1451
HIGH
IBM DB2 9.7-11.1 - Privilege Escalation to Root via DB2 Instance Owner
Sep 12, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-1439
MEDIUM
IBM DB2 9.7-11.1 - Privilege Escalation to Root via DB2 Instance Owner
Sep 12, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1438
MEDIUM
IBM DB2 9.7-11.1 - Privilege Escalation to Root
Sep 12, 2017
CVSS 6.7
EPSS 0.00
CVE-2017-1434
MEDIUM
IBM DB2 11.1 - Exposure of Sensitive Information in Error Log
Sep 12, 2017
CVSS 4.7
EPSS 0.00
CVE-2017-1352
MEDIUM
IBM Maximo Asset Mgmt <7.6 - Command Injection
Sep 12, 2017
CVSS 5.5
EPSS 0.01
Products
websphere_application_server 465
aix 400
db2 339
rational_quality_manager 202
sterling_b2b_integrator 195
qradar_security_information_and_event_manager 190
infosphere_information_server 189
maximo_asset_management 182
rational_doors_next_generation 153
rational_team_concert 142
rational_collaborative_lifecycle_management 141
rational_engineering_lifecycle_manager 141
websphere_portal 126
security_guardium 112
cognos_analytics 104
sterling_file_gateway 93
vios 92
rational_rhapsody_design_manager 90
security_verify_access 90
websphere_mq 89
business_process_manager 88
lotus_domino 86
api_connect 81
rational_software_architect_design_manager 81
lotus_notes 71
security_key_lifecycle_manager 70
db2_universal_database 66
concert 65
i 65
smartcloud_control_desk 65
Quick Filters