Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Cognos Analytics MEDIUM 6.1
CVE-2021-39047

IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows user…

Fix: 11.1.7+
Fix from $1,600 2022-06-24
Spectrum Copy Data Management MEDIUM 5.4
CVE-2022-30611

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied inpu…

Fix: after 2.2.15.0
Fix from $1,600 2022-06-10
Jazz Team Server MEDIUM 5.4
CVE-2021-39043

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2022-05-20
Datapower Gateway MEDIUM 6.1
CVE-2021-38944

IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection,…

Fix: after 2018.4.1.18
Fix from $1,600 2022-05-18
Jazz Foundation MEDIUM 5.4
CVE-2021-39059

IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows use…

Mitigation only
Fix from $1,600 2022-05-11
Guardium Data Encryption MEDIUM 6.1
CVE-2021-39024

IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2022-05-10
Infosphere Information Server MEDIUM 6.1
CVE-2022-22427

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22322

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-22443

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-04-28
Infosphere Information Server MEDIUM 5.4
CVE-2021-38952

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

No fix yet
Fix from $1,600 2022-04-28
Cognos Analytics MEDIUM 5.4
CVE-2021-38903

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…

Patch available
Fix from $1,600 2022-04-22
Cognos Analytics MEDIUM 5.4
CVE-2021-38946

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2022-04-22
Maximo Asset Management MEDIUM 5.4
CVE-2022-22435

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Patch available
Fix from $1,600 2022-04-21
Maximo Asset Management MEDIUM 5.4
CVE-2022-22436

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Patch available
Fix from $1,600 2022-04-21
Curam Social Program Management MEDIUM 5.4
CVE-2021-39068

IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2022-04-11
Iss Blackice Pc Protection MEDIUM 6.1
CVE-2003-5003

A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipula…

Mitigation only
Fix from $1,600 2022-03-28
Spectrum Copy Data Management MEDIUM 5.4
CVE-2021-39055

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Cognos Analytics Mobile MEDIUM 5.4
CVE-2021-39079

IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: 1.1.14+
Fix from $1,600 2022-02-14
Security Verify Access MEDIUM 5.4
CVE-2021-38895

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2022-01-10
I MEDIUM 6.1
CVE-2021-38876

IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2021-12-30
Power System Ac922 \(8335 Gtg\) Firmware MEDIUM 6.1
CVE-2021-38961

IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

Mitigation only
Fix from $1,600 2021-12-27
Business Automation Workflow MEDIUM 5.4
CVE-2021-38893

IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting…

Patch available
Fix from $1,600 2021-12-21
Cloud Pak For Automation MEDIUM 5.4
CVE-2021-38966

IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2021-12-21
Business Automation Workflow MEDIUM 5.4
CVE-2021-38883

IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This …

Patch available
Fix from $1,600 2021-12-17
Cognos Analytics MEDIUM 5.4
CVE-2021-38909

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.1.7+
Fix from $1,600 2021-12-03
Cognos Analytics MEDIUM 6.1
CVE-2021-20493

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 11.1.7+
Fix from $1,600 2021-12-03
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2021-29849

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2021-12-01
Security Guardium Key Lifecycle Manager MEDIUM 5.4
CVE-2021-38982

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Fix: after 4.0.0.3
Fix from $1,600 2021-11-15
Security Siteprotector System MEDIUM 5.4
CVE-2020-4140

IBM Security SiteProtector System 3.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2021-11-12
Qradar Network Security MEDIUM 5.4
CVE-2020-4153

IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Fix: 5.4.0.14 / 5.5.0.9+
Fix from $1,600 2021-11-08