Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29808

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows user…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29809

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows user…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29817

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29818

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29819

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29820

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Tivoli Netcool\/omnibus Webgui MEDIUM 5.4
CVE-2021-29821

IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Fix: 8.1.0.24+
Fix from $1,600 2021-09-20
Financial Transaction Manager MEDIUM 5.4
CVE-2021-29841

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2021-09-14
Planning Analytics MEDIUM 5.4
CVE-2021-29852

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-09-01
Maximo Application Suite MEDIUM 5.4
CVE-2021-29743

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 8.4
Fix from $1,600 2021-08-30
Maximo Application Suite MEDIUM 5.4
CVE-2021-29744

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2021-08-27
Api Connect MEDIUM 5.4
CVE-2020-4706

IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sendi…

Fix: after 5.0.8.10
Fix from $1,600 2021-08-17
Api Connect MEDIUM 5.4
CVE-2020-4707

IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.8.11
Fix from $1,600 2021-08-04
Engineering Lifecycle Optimization Engineering Insights MEDIUM 5.4
CVE-2020-5004

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Mitigation only
Fix from $1,600 2021-07-28
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-20562

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerabi…

Fix: after 6.1.0.2
Fix from $1,600 2021-07-27
Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2020-5031

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19
Engineering Lifecycle Optimization MEDIUM 5.4
CVE-2021-20507

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Mitigation only
Fix from $1,600 2021-07-19
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20361

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20362

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20363

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20364

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20365

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20366

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 4.3.1+
Fix from $1,600 2021-07-13
Cloud Pak For Applications MEDIUM 5.4
CVE-2021-20368

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 4.3.1+
Fix from $1,600 2021-07-13
Tivoli Netcool\/omnibus Gui MEDIUM 5.4
CVE-2021-29803

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2021-07-12
Tivoli Netcool\/omnibus Gui MEDIUM 5.4
CVE-2021-29804

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2021-07-12
Tivoli Netcool\/omnibus Gui MEDIUM 5.4
CVE-2021-29805

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2021-07-12
Tivoli Netcool\/omnibus Gui MEDIUM 5.4
CVE-2021-29822

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2021-07-12
Infosphere Information Server MEDIUM 6.1
CVE-2021-29712

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2021-07-09
Datacap Navigator MEDIUM 5.4
CVE-2020-4935

IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-07-01