Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Doors Next MEDIUM 5.4
CVE-2020-4445

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4522

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Doors Next MEDIUM 5.4
CVE-2020-4546

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Mitigation only
Fix from $1,600 2020-09-02
Infosphere Guardium MEDIUM 5.4
CVE-2012-3341

IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote…

Mitigation only
Fix from $1,600 2020-09-01
Websphere Application Server MEDIUM 6.1
CVE-2020-4575

IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Av…

Fix: 8.5.5.18 / 9.0.5.5+
Fix from $1,600 2020-08-27
Guardium Data Encryption MEDIUM 5.4
CVE-2019-4691

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,600 2020-08-26
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4533

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2020-08-10
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4539

IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Patch available
Fix from $1,600 2020-08-10
Jazz Reporting Service MEDIUM 6.1
CVE-2020-4541

IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2020-08-10
Engineering Test Management MEDIUM 5.4
CVE-2020-4396

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Engineering Workflow Management MEDIUM 5.4
CVE-2020-4525

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Engineering Requirements Management Doors Next MEDIUM 5.4
CVE-2020-4542

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-08-04
Financial Transaction Manager MEDIUM 6.1
CVE-2020-4560

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2020-08-03
Planning Analytics Local MEDIUM 5.4
CVE-2020-4645

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 2.0.9.1
Fix from $1,600 2020-07-29
Intelligent Operations Center MEDIUM 5.4
CVE-2020-4317

IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…

Patch available
Fix from $1,600 2020-07-28
Intelligent Operations Center MEDIUM 5.4
CVE-2020-4318

IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnera…

Patch available
Fix from $1,600 2020-07-28
Filenet Content Manager MEDIUM 5.4
CVE-2020-4447

IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2020-07-23
Engineering Workflow Management MEDIUM 5.4
CVE-2019-4747

IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Patch available
Fix from $1,600 2020-07-16
Collaborative Lifecycle Management MEDIUM 5.4
CVE-2019-4748

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…

Patch available
Fix from $1,600 2020-07-16
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2020-4513

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: after 7.3.2
Fix from $1,600 2020-07-14
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4364

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: after 7.3.2
Fix from $1,600 2020-07-14
Inotes MEDIUM 6.1
CVE-2017-1659

"HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based…

Fix: after 9.0.1.9
Fix from $1,600 2020-07-01
Business Automation Workflow MEDIUM 5.4
CVE-2020-4557

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulne…

Mitigation only
Fix from $1,600 2020-06-29
Maximo Asset Management MEDIUM 5.4
CVE-2020-4223

IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Mitigation only
Fix from $1,600 2020-06-26
Security Secret Server MEDIUM 6.1
CVE-2020-4323

IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Fix: 10.8+
Fix from $1,600 2020-06-24
Doors Next MEDIUM 5.4
CVE-2020-4281

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4295

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Doors Next MEDIUM 5.4
CVE-2020-4297

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Mitigation only
Fix from $1,600 2020-06-19
Api Connect MEDIUM 5.4
CVE-2020-4251

IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: after 5.0.8.8
Fix from $1,600 2020-06-12
Workload Scheduler MEDIUM 5.4
CVE-2020-4380

IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2020-06-11