ibm

8,321 tracked vulnerabilities.

CVE-2014-6086
IBM Security Access Manager 8.x < 8.0.1 and 7.x < 7.0.0 FP10 - Sensitive Information Exposure via Unencrypted HTTP
Dec 18, 2014
EPSS 0.01
CVE-2014-6084
IBM Security Access Manager 7.x/8.x - Information Disclosure via Weak SSL Cipher
Dec 18, 2014
EPSS 0.01
CVE-2014-6083
IBM Security Access Manager 7.x < 7.0.0 FP10 & 8.x < 8.0.1 - Sensitive Cookie Exposure
Dec 18, 2014
EPSS 0.01
CVE-2014-6082
IBM Security Access Manager for Web 7.x < 7.0.0 FP10 and 8.x < 8.0.1 - Authenticated Denial of Service
Dec 18, 2014
EPSS 0.01
CVE-2014-6080
IBM Security Access Manager SQL Injection (Mobile 8.x < 8.0.1, Web 7.x < 7.0.0 FP10, 8.x < 8.0.1)
Dec 18, 2014
EPSS 0.01
CVE-2014-6078
IBM Security Access Manager for Mobile 8.x and Web 7.x-8.x - Improper Access Control
Dec 18, 2014
EPSS 0.01
CVE-2014-6077
IBM Security Access Manager for Web 7.x < 7.0.0 FP10 and 8.x < 8.0.1 - Cross-Site Request Forgery
Dec 18, 2014
EPSS 0.01
CVE-2014-6076
IBM Security Access Manager Mobile/Web Clickjacking (8.x < 8.0.1, 7.x < 7.0.0 FP10)
Dec 18, 2014
EPSS 0.01
CVE-2014-6182
IBM Business Process Manager 8.0.x-8.0.1.3 & 8.5.x-8.5.5 Path Traversal via Process Center Export
Dec 17, 2014
EPSS 0.02
CVE-2014-4844
IBM Business Process Manager 7.5.x-7.5.1.2, 8.0.x-8.0.1.3, 8.5.x-8.5.5 - Access Control Bypass
Dec 17, 2014
EPSS 0.01
CVE-2014-6176
IBM Business Process Manager SSLv3 Downgrade in SCA HTTP Import Binding
Dec 16, 2014
EPSS 0.02
CVE-2014-6210
IBM DB2 9.7-10.5 - Authenticated Denial of Service via ALTER TABLE Column Specification
Dec 12, 2014
EPSS 0.02
CVE-2014-6209
IBM DB2 9.5-10.5 - Authenticated Denial of Service via ALTER TABLE Identity Column
Dec 12, 2014
EPSS 0.02
CVE-2014-6145
IBM Cognos Business Intelligence 10.1-10.2.1.1 - Authenticated Cross-Site Scripting via Crafted URL
Dec 12, 2014
EPSS 0.01
CVE-2014-6138
IBM WebSphere DataPower XC10 Appliance 2.1-2.5 - Authenticated Unauthorized Data Access
Dec 12, 2014
EPSS 0.01
CVE-2014-4815
IBM Rational Lifecycle Integration Adapter for Windchill <1.0.1 - I...
Dec 12, 2014
EPSS 0.01
CVE-2014-6215
IBM WebSphere Portal <8.5.0 - XSS
Dec 11, 2014
EPSS 0.01
CVE-2014-6163
IBM WebSphere DataPower XC10 Appliance 2.1 and 2.5 - Authenticated Cross-Site Scripting via Crafted URL
Dec 11, 2014
EPSS 0.01
CVE-2014-6143
IBM WebSphere DataPower XC10 2.1/2.5 - Sensitive Information Exposure via Local Response Reading
Dec 11, 2014
EPSS 0.00
CVE-2014-3058
IBM WebSphere DataPower XC10 Appliance 2.1 and 2.5 - Authenticated Cross-Site Request Forgery
Dec 11, 2014
EPSS 0.01
CVE-2014-6114
IBM Operational Decision Manager - XML External Entity Injection in Hosted Transparent Decision Service
Dec 11, 2014
EPSS 0.02
CVE-2014-6140
IBM Tivoli Endpoint Manager Mobile Device Management < 9.0 - Remote Code Execution via HMAC Token Cookie
Dec 06, 2014
EPSS 0.06
CVE-2014-3099
IBM Systems Director <6.3.5 - Info Disclosure
Dec 06, 2014
EPSS 0.00
CVE-2014-3068
IBM Java Runtime Environment Private Key Exposure via CMS Keystore Brute Force
Dec 02, 2014
EPSS 0.01
CVE-2014-3065
IBM Java Runtime Environment Local Code Execution via Shared Classes Cache
Dec 02, 2014
EPSS 0.01