Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2019-4431

IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Mitigation only
Fix from $1,600 2020-02-12
Security Identity Manager MEDIUM 5.4
CVE-2019-4451

IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Fix: 6.0.0.22+
Fix from $1,600 2020-02-04
Security Secret Server MEDIUM 6.1
CVE-2019-4632

IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Fix: 10.7.000059+
Fix from $1,600 2020-01-28
Chatbot With Ibm Watson MEDIUM 6.1
CVE-2020-7239

The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScri…

Fix: 0.8.21+
Fix from $1,600 2020-01-21
Cognos Analytics MEDIUM 5.4
CVE-2019-4623

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2019-12-30
Financial Transaction Manager For Multiplatform MEDIUM 6.1
CVE-2019-4744

IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2019-12-20
Cognos Analytics MEDIUM 5.4
CVE-2019-4555

IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Fix: 11.1.4+
Fix from $1,600 2019-12-20
Business Automation Workflow MEDIUM 5.4
CVE-2019-4426

The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This …

Fix: 5.3.2+
Fix from $1,600 2019-12-13
Spectrum Scale MEDIUM 5.4
CVE-2019-4665

IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: after 5.0.4.0
Fix from $1,600 2019-12-11
Websphere Application Server MEDIUM 5.4
CVE-2019-4663

IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Fix: 19.0.0.11+
Fix from $1,600 2019-12-10
Watson Assistant For Ibm Cloud Pak For Data MEDIUM 5.4
CVE-2019-4428

IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 1.3.0
Fix from $1,600 2019-12-09
Planning Analytics MEDIUM 5.4
CVE-2019-4611

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2019-12-09
Cloud Pak System MEDIUM 5.4
CVE-2019-4098

IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2019-12-03
Cloud Pak System MEDIUM 5.4
CVE-2019-4226

IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2019-12-03
Cloud Pak System MEDIUM 5.4
CVE-2019-4467

IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2019-12-03
Cloud Pak System MEDIUM 5.4
CVE-2019-4468

IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2019-12-03
Tivoli Netcool\/impact MEDIUM 5.4
CVE-2019-4569

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Fix: after 7.1.0.16
Fix from $1,600 2019-11-22
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2019-4581

IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 7.3.1
Fix from $1,600 2019-11-09
Cognos Analytics MEDIUM 6.1
CVE-2019-4645

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2019-11-09
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2019-4454

IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 7.3.1
Fix from $1,600 2019-11-09
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2019-4470

IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 7.3.1
Fix from $1,600 2019-11-09
I MEDIUM 6.1
CVE-2019-4450

IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

Patch available
Fix from $1,600 2019-11-09
Maximo Asset Management MEDIUM 5.4
CVE-2019-4486

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Fix: 7.6.0.10 / 7.6.1.1+
Fix from $1,600 2019-10-24
Cloud Orchestrator MEDIUM 5.4
CVE-2019-4459

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This …

Fix: after 2.5.0.9
Fix from $1,600 2019-10-24
Security Key Lifecycle Manager MEDIUM 6.1
CVE-2019-4564

IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 3.0.1.1
Fix from $1,600 2019-10-04
Security Directory Server MEDIUM 6.1
CVE-2019-4542

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Patch available
Fix from $1,600 2019-10-02
Jazz Reporting Service MEDIUM 5.4
CVE-2019-4494

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability…

Patch available
Fix from $1,600 2019-10-01
Jazz Reporting Service MEDIUM 5.4
CVE-2019-4495

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability…

Patch available
Fix from $1,600 2019-10-01
Jazz Reporting Service MEDIUM 5.4
CVE-2019-4497

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability…

Patch available
Fix from $1,600 2019-10-01
Websphere Extreme Scale MEDIUM 5.4
CVE-2019-4115

IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Fix: 8.6.1.3+
Fix from $1,600 2019-09-30