ibm

8,321 tracked vulnerabilities.

CVE-2014-0909
IBM Rational License Key Server 8.1.4.x < 8.1.4.4 - Session Cookie Exposure via Insecure Flag
Sep 10, 2014
EPSS 0.02
CVE-2014-0877
IBM Cognos TM1 10.2.0.2-10.2.2.0 - Unauthenticated Access Restriction Bypass via Rights Page Link
Sep 05, 2014
EPSS 0.01
CVE-2014-0863
IBM Cognos TM1 - Authenticated Cleartext Password Exposure via Memory Inspection
Sep 05, 2014
EPSS 0.01
CVE-2014-4805
IBM DB2 10.5 - Exposure of Sensitive Information via Temporary Files in CDE Table LOAD Operations
Sep 04, 2014
EPSS 0.00
CVE-2014-4759
IBM Business Process Manager 8.5.x-8.5.5 - Authenticated Information Disclosure via Content Management Ajax Service
Sep 04, 2014
EPSS 0.01
CVE-2014-4758
IBM Business Process Manager 7.5.x-8.5.5 - Authenticated Access Control Bypass via callService URL
Sep 04, 2014
EPSS 0.01
CVE-2014-3095
IBM DB2 9.5-10.5 - Authenticated Denial of Service via UNION Clause in Subquery
Sep 04, 2014
EPSS 0.02
CVE-2014-3094
IBM DB2 9.7-10.5 - Authenticated Remote Code Execution via ALTER MODULE Statement
Sep 04, 2014
EPSS 0.05
CVE-2014-3075
IBM Business Process Manager 7.5.x-8.5.5 - Authenticated Stored Cross-Site Scripting via Uploaded File
Sep 04, 2014
EPSS 0.01
CVE-2014-4806 MEDIUM
IBM Security AppScan Enterprise <9.0.0.1 - Info Disclosure
Aug 29, 2014
CVSS 5.5
EPSS 0.00
CVE-2014-3093
IBM PowerVC 1.2.0-1.2.1 - Cleartext Password Exposure in Multiple Components
Aug 29, 2014
EPSS 0.00
CVE-2014-3084
IBM Maximo Asset Management 6.1-6.5, 7.1-7.1.1.13, 7.5-7.5.0.6 - Authenticated Access Control Bypass
Aug 29, 2014
EPSS 0.02
CVE-2014-3024
IBM Maximo Asset Management 7.1-7.1.1.12 and 7.5-7.5.0.6 - Authenticated Cross-Site Request Forgery
Aug 29, 2014
EPSS 0.01
CVE-2014-0897
IBM Flex System Manager 1.2.0.x-1.3.1.x - Authenticated Weak Encryption in Configuration Patterns
Aug 29, 2014
EPSS 0.01
CVE-2014-0888
IBM Worklight Foundation 5.x-6.x - Authenticated Application Authenticity Bypass
Aug 29, 2014
EPSS 0.01
CVE-2014-3061
IBM Emptoris Spend Analysis 9.5.x-9.5.0.3, 10.0.1.x-10.0.1.2, 10.0.2.x-10.0.2.3 - Cross-Site Request Forgery
Aug 26, 2014
EPSS 0.01
CVE-2014-3041
IBM Emptoris Contract Management 9.5.x-10.0.2.x - Authenticated SQL Injection
Aug 26, 2014
EPSS 0.01
CVE-2014-3035
IBM Emptoris Spend Analysis XSS via Crafted URL (9.5.x < 9.5.0.4, 10.0.1.x < 10.0.1.3, 10.0.2.x < 10.0.2.4)
Aug 26, 2014
EPSS 0.01
CVE-2014-3034
IBM Emptoris Contract Management 9.5.x-10.0.2.x - Authenticated Cross-Site Scripting via Crafted URL
Aug 26, 2014
EPSS 0.01
CVE-2014-4790
IBM Emptoris Sourcing Portfolio <10.0.2.4 - XSS
Aug 26, 2014
EPSS 0.01
CVE-2014-3040
IBM Emptoris Spend Analysis 9.5.x < 9.5.0.4, 10.0.1.x < 10.0.1.3, 10.0.2.x < 10.0.2.4 - Cross-Site Request Forgery
Aug 26, 2014
EPSS 0.01
CVE-2014-3033
IBM Emptoris Sourcing Portfolio XSS via Crafted URL
Aug 26, 2014
EPSS 0.01
CVE-2014-4767
IBM WebSphere Application Server (WAS) Liberty Profile <8.5.5.3 - RCE
Aug 22, 2014
EPSS 0.03
CVE-2014-4764
IBM WebSphere Application Server <8.0.0.10 & <8.5.5.3 - DoS
Aug 22, 2014
EPSS 0.02
CVE-2014-3089
IBM Rational Directory Server 5.1.1.x-5.1.1.2, 5.2.x-5.2.1 & Administrator 6.0 - Cleartext Password Exposure
Aug 22, 2014
EPSS 0.00