ibm

8,321 tracked vulnerabilities.

CVE-2016-0314 MEDIUM
IBM Jazz Reporting Service <6.0.1 - CSRF
Jul 08, 2016
CVSS 6.5
EPSS 0.01
CVE-2016-0313 MEDIUM
IBM Jazz Reporting Service <5.0.2-6.0.1 - XSS
Jul 08, 2016
CVSS 5.4
EPSS 0.01
CVE-2016-0287 HIGH
IBM i Access 7.1 - Exposure of Sensitive Information via Registry Password Discovery
Jul 08, 2016
CVSS 7.8
EPSS 0.00
CVE-2016-0271 HIGH
IBM UrbanCode Deploy <6.0.1.14-6.2.1.1 - Privilege Escalation
Jul 08, 2016
CVSS 8.2
EPSS 0.00
CVE-2016-0252 MEDIUM
IBM Control Center <6.0.0.1-5.4.2.1 - Info Disclosure
Jul 08, 2016
CVSS 5.1
EPSS 0.00
CVE-2016-2923 HIGH
IBM WebSphere Application Server 8.5-8.5.5.9 & Liberty <16.0.0.2 - Unauthorized Cookie Access
Jul 07, 2016
CVSS 7.5
EPSS 0.02
CVE-2016-0389 MEDIUM
IBM WebSphere Application Server 8.5.5.2-8.5.5.9 - Exposure of Sensitive Information via Admin Center
Jul 07, 2016
CVSS 5.3
EPSS 0.02
CVE-2016-0230 MEDIUM
IBM Power HMC <8.5.0 - Privilege Escalation
Jul 07, 2016
CVSS 6.8
EPSS 0.00
CVE-2016-2894 LOW
IBM Spectrum Protect 5.5-6.3 < 6.3.2.6, 6.4 < 6.4.3.3, 7.1 < 7.1.6 - Unauthorized Sensitive Data Exposure via Symlink
Jul 03, 2016
CVSS 2.5
EPSS 0.00
CVE-2016-2863 HIGH
IBM WebSphere Commerce 7.0 FP8, 8.0.0.x < 8.0.0.10, 8.0.1.x < 8.0.1.2 - CSRF
Jul 03, 2016
CVSS 8.0
EPSS 0.01
CVE-2016-2862 MEDIUM
IBM WebSphere Commerce 6.0-6.0.0.11, 7.0 < 7.0.0.9 iFix 3, 8.0 < 8.0.0.5 - Cross-Site Scripting via Crafted URL
Jul 03, 2016
CVSS 6.1
EPSS 0.01
CVE-2016-0359 MEDIUM
IBM WebSphere Application Server <7.0.0.43, <8.0.0.13, <8.5 Full <8...
Jul 03, 2016
CVSS 6.1
EPSS 0.01
CVE-2016-0346 MEDIUM
IBM Cognos Business Intelligence <10.2 - XSS
Jul 03, 2016
CVSS 5.4
EPSS 0.01
CVE-2016-0221 MEDIUM
IBM Cognos Business Intelligence - Authenticated Cross-Site Scripting via Crafted URL
Jul 03, 2016
CVSS 5.4
EPSS 0.01
CVE-2016-3956 HIGH
npm <2.15.1,3.x <3.8.3 - Info Disclosure
Jul 02, 2016
CVSS 7.5
EPSS 0.07
CVE-2016-2968 MEDIUM
IBM Security QRadar Incident Forensics 7.2.x - Authentication Bypass
Jul 02, 2016
CVSS 6.5
EPSS 0.01
CVE-2016-2961 MEDIUM
IBM Integration Bus 9-10 and WebSphere Message Broker 8 - Sensitive Information Exposure via Malformed POST Request
Jul 02, 2016
CVSS 5.3
EPSS 0.01
CVE-2016-2883 MEDIUM
IBM TRIRIGA 3.3-3.5.0.1 Authenticated XSS via Crafted URL
Jul 02, 2016
CVSS 5.4
EPSS 0.01
CVE-2016-2882 MEDIUM
IBM TRIRIGA 3.3-3.3.2.5, 3.4-3.4.2.3, 3.5-3.5.0.1 - Sensitive Info Exposure via HTTP
Jul 02, 2016
CVSS 4.3
EPSS 0.01
CVE-2016-2872 MEDIUM
IBM Security QRadar SIEM and Incident Forensics 7.2.x < 7.2.7 - Path Traversal via Crafted URL
Jul 02, 2016
CVSS 5.3
EPSS 0.02
CVE-2016-2870 LOW
IBM WebSphere DataPower XC10 Appliance Firmware 2.1 and 2.5 - Authenticated Denial of Service via CLI Buffer Overflow
Jul 02, 2016
CVSS 2.7
EPSS 0.02
CVE-2016-2868 LOW
IBM QRadar Security Information and Event Manager < 7.2.7 - Authenticated XML External Entity Injection
Jul 02, 2016
CVSS 2.7
EPSS 0.01
CVE-2016-2867 HIGH
IBM InfoSphere Streams < 4.0.1.2 and IBM Streams < 4.1.1.1 - Privilege Escalation via runAsUser Feature
Jul 02, 2016
CVSS 7.0
EPSS 0.00
CVE-2016-2861 LOW
IBM WebSphere eXtreme Scale Sensitive Information Exposure via Improper Data Encryption
Jul 02, 2016
CVSS 3.7
EPSS 0.01
CVE-2016-0400 MEDIUM
IBM WebSphere eXtreme Scale <7.1.0.3-8.6.0.8 - CRLF Injection
Jul 02, 2016
CVSS 6.1
EPSS 0.02