Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Planning Analytics MEDIUM 5.4
CVE-2021-20477

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2021-06-29
Business Automation Workflow MEDIUM 5.4
CVE-2021-29775

IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. Th…

Patch available
Fix from $1,600 2021-06-28
Security Verify MEDIUM 5.4
CVE-2021-29677

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arb…

Fix: 10.9.66+
Fix from $1,600 2021-06-25
Financial Transaction Manager MEDIUM 5.4
CVE-2020-5000

IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2021-06-15
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4977

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-5030

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20338

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-29668

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-29670

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2021-06-02
Cognos Analytics HIGH 8.8
CVE-2020-4520

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would exe…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics MEDIUM 5.4
CVE-2019-4653

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2021-06-01
Cognos Analytics MEDIUM 5.4
CVE-2020-4354

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2021-06-01
Security Guardium MEDIUM 6.1
CVE-2021-20386

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-05-24
Maximo Asset Management MEDIUM 5.4
CVE-2021-20374

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2021-05-19
Control Center MEDIUM 5.4
CVE-2021-20528

IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2021-05-19
Qradar User Behavior Analytics MEDIUM 6.1
CVE-2021-20392

IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Fix: 4.1.0+
Fix from $1,600 2021-05-14
Openpages Grc Platform MEDIUM 5.4
CVE-2020-4535

IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: 8.1.0.2+
Fix from $1,600 2021-05-11
Cloud Pak For Security MEDIUM 6.1
CVE-2021-20577

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2021-05-10
Control Desk MEDIUM 5.4
CVE-2021-20559

IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2021-05-10
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2021-20397

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.3.3 / 7.4.2+
Fix from $1,600 2021-05-05
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4929

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.3.3 / 7.4.2+
Fix from $1,600 2021-05-05
Flashsystem 900 Firmware MEDIUM 5.4
CVE-2020-4987

The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. Th…

Fix: 1.5.2.9 / 1.6.1.3+
Fix from $1,600 2021-05-04
Content Navigator MEDIUM 5.4
CVE-2021-20448

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20549

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Content Navigator MEDIUM 5.4
CVE-2021-20550

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mitigation only
Fix from $1,600 2021-04-27
Spectrum Scale MEDIUM 5.4
CVE-2021-29666

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Fix: after 5.1.0.2
Fix from $1,600 2021-04-27
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2021-20519

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Patch available
Fix from $1,600 2021-04-12
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2020-4920

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2021-04-12
Edge Application Manager MEDIUM 5.4
CVE-2020-4792

IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

Patch available
Fix from $1,600 2021-04-05
Infosphere Information Server MEDIUM 5.4
CVE-2020-4997

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2021-04-05