| CVE-2015-7820 |
high |
— |
7.1 |
|
|
lenovoibm |
11y ago |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privilege… |
| CVE-2015-7819 |
medium |
— |
5.0 |
|
|
lenovoibm |
11y ago |
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a… |
| CVE-2015-7818 |
high |
— |
7.2 |
|
|
ibmlenovo |
11y ago |
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM … |
| CVE-2015-7817 |
high |
— |
7.1 |
|
|
ibmlenovo |
11y ago |
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privilege… |
| CVE-2015-7412 |
low |
— |
2.6 |
|
|
ibm |
11y ago |
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext da… |
| CVE-2015-5044 |
low |
— |
3.3 |
|
|
ibm |
11y ago |
The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets. |
| CVE-2015-5043 |
high |
— |
7.2 |
|
|
ibm |
11y ago |
diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences. |
| CVE-2015-5019 |
medium |
— |
5.5 |
|
|
ibm |
11y ago |
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement. |
| CVE-2015-5015 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST URL. |
| CVE-2015-5005 |
high |
— |
8.5 |
|
|
ibm |
11y ago |
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list. |
| CVE-2015-4966 |
medium |
— |
6.5 |
|
|
ibm |
11y ago |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFI… |
| CVE-2015-4963 |
high |
— |
7.5 |
|
|
ibm |
11y ago |
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via un… |
| CVE-2015-4940 |
low |
— |
2.1 |
|
|
apacheibm |
11y ago |
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information… |
| CVE-2015-4928 |
medium |
— |
4.3 |
|
|
apacheibm |
11y ago |
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive infor… |
| CVE-2015-2017 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitra… |
| CVE-2015-1999 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs… |
| CVE-2015-1997 |
medium |
— |
6.8 |
|
|
ibm |
11y ago |
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hijack the authentication of arbitrary users for req… |
| CVE-2015-1996 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information … |
| CVE-2015-1995 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote attackers to inject arbitrary web script or HTML via a crafted UR… |
| CVE-2015-1994 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtai… |
| CVE-2015-1993 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these… |
| CVE-2015-1989 |
medium |
— |
6.5 |
|
|
ibm |
11y ago |
SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2015-7395 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 F… |
| CVE-2015-5021 |
medium |
— |
5.5 |
|
|
ibm |
11y ago |
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors. |
| CVE-2015-4927 |
high |
— |
7.2 |
|
|
ibm |
11y ago |
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files,… |
| CVE-2015-5040 |
high |
— |
7.5 |
|
|
ibm |
11y ago |
Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash)… |
| CVE-2015-4997 |
medium |
— |
6.8 |
|
|
ibm |
11y ago |
IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request. |
| CVE-2015-4994 |
high |
— |
7.5 |
|
|
ibm |
11y ago |
Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash)… |
| CVE-2014-8912 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which … |
| CVE-2015-5014 |
critical |
— |
9.3 |
|
|
ibm |
11y ago |
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation. |
| CVE-2015-5011 |
low |
— |
3.2 |
|
|
ibm |
11y ago |
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass int… |
| CVE-2015-4981 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory v… |
| CVE-2015-4974 |
high |
— |
7.2 |
|
|
ibm |
11y ago |
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via … |
| CVE-2015-4929 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive i… |
| CVE-2015-5024 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticat… |
| CVE-2015-5022 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a p… |
| CVE-2015-4992 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. |
| CVE-2015-4973 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers t… |
| CVE-2015-4971 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x befo… |
| CVE-2015-4967 |
medium |
— |
6.5 |
|
|
ibm |
11y ago |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 a… |
| CVE-2015-4965 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x b… |
| CVE-2015-4964 |
medium |
— |
6.0 |
|
|
ibm |
11y ago |
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by… |
| CVE-2015-4944 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.… |
| CVE-2015-4939 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0… |
| CVE-2015-4930 |
critical |
— |
9.0 |
|
|
ibm |
11y ago |
IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access. |
| CVE-2015-2031 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a cr… |
| CVE-2015-2030 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack. |
| CVE-2015-2029 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier. |
| CVE-2015-2028 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting … |
| CVE-2015-2027 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an una… |
| CVE-2015-2026 |
medium |
— |
6.0 |
|
|
ibm |
11y ago |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrar… |
| CVE-2015-2025 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captur… |
| CVE-2015-2016 |
critical |
— |
9.0 |
|
|
ibm |
11y ago |
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unkno… |
| CVE-2015-2011 |
critical |
— |
9.0 |
|
|
ibm |
11y ago |
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via un… |
| CVE-2015-1988 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Stor… |
| CVE-2015-1983 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. |
| CVE-2015-1969 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other… |
| CVE-2015-1934 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001… |
| CVE-2015-1933 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001… |
| CVE-2015-4955 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenti… |
| CVE-2015-1888 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.2 before 2.0.2-ICN-FP007 and 2.0.3 before 2.0.3-ICN-FP003, as used in Content Manager, FileNet Content Manager, Content Foundatio… |
| CVE-2015-0195 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject … |
| CVE-2015-0145 |
medium |
— |
6.8 |
|
|
ibm |
11y ago |
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack … |
| CVE-2015-0144 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitra… |
| CVE-2015-0143 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages. |
| CVE-2015-0142 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and… |
| CVE-2015-0141 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request. |
| CVE-2014-8916 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitra… |
| CVE-2015-4947 |
critical |
— |
9.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere … |
| CVE-2015-4980 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors. |
| CVE-2015-1943 |
high |
— |
7.8 |
|
|
ibm |
11y ago |
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial… |
| CVE-2015-2013 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call. |
| CVE-2015-2018 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authen… |
| CVE-2015-4950 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; T… |
| CVE-2015-1992 |
high |
— |
7.2 |
|
|
ibm |
11y ago |
IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, 6.3.2.x, 6.3.3.x, 6.3.5.0, and 6.3.6.0 improperly processes events, which allows local users to gain privileges via unspecified … |
| CVE-2015-6557 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: D… |
| CVE-2015-4949 |
low |
— |
2.1 |
|
|
ibm |
11y ago |
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, a… |
| CVE-2015-2015 |
medium |
— |
4.3 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in pubnames.ntf (aka the Directory template) in the web server in IBM Domino before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via a… |
| CVE-2015-2014 |
medium |
— |
5.8 |
|
|
ibm |
11y ago |
Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att… |
| CVE-2015-4938 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vector… |
| CVE-2015-1932 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sens… |
| CVE-2015-4936 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors. |
| CVE-2015-4935 |
critical |
— |
10.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability … |
| CVE-2015-4934 |
critical |
— |
10.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability … |
| CVE-2015-4933 |
critical |
— |
10.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability … |
| CVE-2015-4932 |
critical |
— |
10.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability … |
| CVE-2015-4931 |
critical |
— |
10.0 |
|
|
ibm |
11y ago |
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability … |
| CVE-2015-1987 |
high |
— |
7.8 |
|
|
ibm |
11y ago |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 an… |
| CVE-2015-1958 |
high |
— |
7.8 |
|
|
ibm |
11y ago |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 an… |
| CVE-2015-1956 |
high |
— |
7.8 |
|
|
ibm |
11y ago |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 an… |
| CVE-2015-1955 |
high |
— |
7.8 |
|
|
ibm |
11y ago |
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data. |
| CVE-2015-1904 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is ena… |
| CVE-2015-4945 |
medium |
— |
5.0 |
|
|
ibm |
11y ago |
Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a cr… |
| CVE-2015-1906 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 th… |
| CVE-2015-1905 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated us… |
| CVE-2015-1984 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary pro… |
| CVE-2015-1982 |
medium |
— |
4.0 |
|
|
ibm |
11y ago |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which … |
| CVE-2015-1980 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. |
| CVE-2015-1979 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted in… |
| CVE-2015-1968 |
low |
— |
3.5 |
|
|
ibm |
11y ago |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitra… |