Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4663

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4664

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2020-4666

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2021-01-08
Emptoris Contract Management MEDIUM 5.4
CVE-2020-4892

IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: 10.1.3.30+
Fix from $1,600 2021-01-07
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2020-4895

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Content Navigator MEDIUM 6.4
CVE-2020-4757

IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed a…

Patch available
Fix from $1,600 2020-12-21
Security Key Lifecycle Manager MEDIUM 5.4
CVE-2020-4845

IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: 3.0.1.5 / 4.0.0.2+
Fix from $1,600 2020-12-17
Sterling B2b Integrator MEDIUM 6.1
CVE-2020-4657

IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.0.3.2
Fix from $1,600 2020-12-16
Sterling File Gateway MEDIUM 6.1
CVE-2020-4658

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 6.0.3.2
Fix from $1,600 2020-12-16
Jazz Reporting Service MEDIUM 5.4
CVE-2020-4718

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbi…

Patch available
Fix from $1,600 2020-11-19
Business Automation Workflow MEDIUM 5.4
CVE-2020-4672

IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2020-11-16
Content Navigator MEDIUM 5.4
CVE-2020-4704

IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2020-11-10
Content Navigator MEDIUM 5.4
CVE-2020-4760

IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Mitigation only
Fix from $1,600 2020-11-10
Spectrum Scale MEDIUM 6.1
CVE-2020-4748

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.5.2
Fix from $1,600 2020-10-20
Sterling B2b Integrator MEDIUM 5.4
CVE-2020-4564

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-si…

Fix: after 6.0.3.1
Fix from $1,600 2020-10-20
Spectrum Scale MEDIUM 5.4
CVE-2020-4755

IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Fix: after 5.0.5.2
Fix from $1,600 2020-10-20
Infosphere Information Server MEDIUM 5.4
CVE-2020-4741

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2020-10-12
Infosphere Information Server MEDIUM 5.2
CVE-2020-4740

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Patch available
Fix from $1,600 2020-10-12
Security Guardium MEDIUM 5.4
CVE-2020-4680

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-10-12
Security Guardium MEDIUM 5.4
CVE-2020-4681

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 5.4
CVE-2020-4775

A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to in…

Mitigation only
Fix from $1,600 2020-10-12
Security Access Manager MEDIUM 6.1
CVE-2019-4725

IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Fix: 9.0.7.0+
Fix from $1,600 2020-10-06
Data Risk Manager MEDIUM 5.4
CVE-2020-4615

IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 2.0.6.4+
Fix from $1,600 2020-09-22
Aspera Shares MEDIUM 6.1
CVE-2020-4731

IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Fix: after 1.9.14
Fix from $1,600 2020-09-21
Bladecenter Advanced Management Module Firmware MEDIUM 6.1
CVE-2020-8339

A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…

Fix: 3.68n+
Fix from $1,600 2020-09-15
Business Automation Workflow MEDIUM 5.4
CVE-2020-4530

IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability …

Fix: 8.0.1.0 / 8.5.7.0+
Fix from $1,600 2020-09-15
Websphere Application Server MEDIUM 5.4
CVE-2020-4578

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Fix: after 9.0.5.5
Fix from $1,600 2020-09-10
Business Automation Workflow MEDIUM 5.4
CVE-2020-4516

IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerab…

Patch available
Fix from $1,600 2020-09-08
Business Automation Workflow MEDIUM 5.4
CVE-2020-4698

IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This v…

Patch available
Fix from $1,600 2020-09-08
Infosphere Information Server MEDIUM 5.4
CVE-2020-4702

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Mitigation only
Fix from $1,600 2020-09-04