Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Security Guardium MEDIUM 6.1
CVE-2020-4183

IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2020-06-04
Security Guardium MEDIUM 6.1
CVE-2020-4182

IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2020-06-03
Planning Analytics Local MEDIUM 6.1
CVE-2020-4503

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 5.4
CVE-2020-4431

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 6.1
CVE-2020-4366

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 5.4
CVE-2020-4360

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Fix: 2.0.9.1+
Fix from $1,600 2020-06-02
Planning Analytics Local MEDIUM 5.4
CVE-2020-4306

IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: after 2.0.9
Fix from $1,600 2020-05-29
Jazz Reporting Service MEDIUM 5.4
CVE-2020-4419

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2020-05-28
Spectrum Scale MEDIUM 5.4
CVE-2020-4358

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: after 5.0.4.4
Fix from $1,600 2020-05-27
Infosphere Information Server MEDIUM 5.4
CVE-2020-4298

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Patch available
Fix from $1,600 2020-05-19
Infosphere Information Server On Cloud MEDIUM 5.4
CVE-2020-4384

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2020-05-06
Control Desk MEDIUM 6.1
CVE-2019-4644

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Patch available
Fix from $1,600 2020-04-17
Control Desk MEDIUM 5.4
CVE-2019-4749

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Patch available
Fix from $1,600 2020-04-17
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4268

IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Doors Next Generation MEDIUM 5.4
CVE-2020-4252

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2020-04-08
Rational Quality Manager MEDIUM 5.4
CVE-2019-4602

IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Patch available
Fix from $1,600 2020-04-08
Doors Next Generation MEDIUM 5.4
CVE-2019-4737

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2020-04-08
Doors Next Generation MEDIUM 5.4
CVE-2019-4740

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2020-04-08
Doors Next Generation MEDIUM 5.4
CVE-2019-4746

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…

Patch available
Fix from $1,600 2020-04-08
Websphere Application Server MEDIUM 6.1
CVE-2020-4303

IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 20.0.0.3
Fix from $1,600 2020-04-02
Websphere Application Server MEDIUM 6.1
CVE-2020-4304

IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 20.0.0.3
Fix from $1,600 2020-04-02
Tivoli Netcool\/impact MEDIUM 5.4
CVE-2020-4235

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 7.1.0.17
Fix from $1,600 2020-03-31
Tivoli Netcool\/impact MEDIUM 6.1
CVE-2019-4681

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 7.1.0.17
Fix from $1,600 2020-03-24
Jazz For Service Management MEDIUM 5.4
CVE-2019-4718

IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-23
Tivoli Workload Scheduler MEDIUM 5.4
CVE-2019-4608

IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Mitigation only
Fix from $1,600 2020-03-10
Infosphere Information Server MEDIUM 5.4
CVE-2020-4162

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2020-03-10
Tivoli Netcool\/omnibus MEDIUM 5.4
CVE-2020-4196

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-03
Tivoli Netcool\/omnibus MEDIUM 5.4
CVE-2020-4198

IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2020-03-03
Sterling B2b Integrator MEDIUM 5.4
CVE-2019-4596

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 5.2.6.5
Fix from $1,600 2020-02-26
Control Desk MEDIUM 5.4
CVE-2019-4429

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Patch available
Fix from $1,600 2020-02-19