Ibm
ibm
8,252 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,252)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 6.8 MEDIUM· v3 2.1 LOW· v2 IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored credentials. IBM X-Force ID: 130914. |
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more |
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...Show more |
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hija...Show more |
1Ibm 1Engineering Requirements Management Doors Feb 5, 2025 Jan 26, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825. |
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more |
1Ibm 1Tealeaf Customer Experience Nov 21, 2024 Jan 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to vie...Show more |
1Ibm 1Tealeaf Customer Experience Nov 21, 2024 Jan 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740. |
1Ibm 1Tealeaf Customer Experience Nov 21, 2024 Jan 26, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass secu...Show more |
2Ibm Lenova42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreNov 21, 2024 Jan 26, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a hi...Show more |
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 13...Show more |
1Ibm 1Curam Social Program Management Nov 21, 2024 Jan 19, 2018 N/A· v4 5.0 MEDIUM· v3 6.0 MEDIUM· v2 IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 within Citizen Portal could allow an authenticated user to withdraw other user's submitted applications from the system and possibly obtain privileges. I...Show more |
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164. |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jan 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users...Show more |
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the...Show more |
IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399. |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Jan 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote at...Show more |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Jan 16, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote at...Show more |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Jan 16, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending...Show more |