Ibm
ibm
8,252 CVEs • 1,572 products
Products (1,572)
Click to collapseToggle
Products (1,572)
Click to collapse
CVEs (8,252)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Curam Social Program Management May 13, 2026 Aug 2, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa...Show more |
1Ibm 1Websphere Mq Internet Pass Thru May 13, 2026 Aug 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156. |
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257 |
1Ibm 2Mobilefirst Platform Foundation WorklightMay 13, 2026 Aug 1, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter is "scope"; if yo...Show more |
IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more |
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379. |
1Ibm 2Api Connect Api ManagementMay 13, 2026 Jul 31, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160. |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. |
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...Show more |
IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906. |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remot...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may pr...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a use...Show more |
1Ibm 1Infosphere Master Data Management Server May 13, 2026 Jul 31, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte...Show more |