Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Content Navigator MEDIUM 5.4
CVE-2019-4571

IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Mitigation only
Fix from $1,600 2019-09-25
Websphere Application Server MEDIUM 5.4
CVE-2019-4270

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
Cognos Analytics MEDIUM 5.4
CVE-2019-4342

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Patch available
Fix from $1,600 2019-09-17
Jazz For Service Management MEDIUM 6.1
CVE-2019-4186

IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By se…

Mitigation only
Fix from $1,600 2019-09-05
Business Automation Workflow MEDIUM 5.4
CVE-2019-4149

IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.…

Fix: after 18.0.0.2
Fix from $1,600 2019-09-05
Emptoris Spend Analysis MEDIUM 5.4
CVE-2019-4482

IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip…

Fix: after 10.1.3
Fix from $1,600 2019-08-20
Cloud Private MEDIUM 5.4
CVE-2019-4120

IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Fix: after 3.1.2
Fix from $1,600 2019-08-20
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2019-4211

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: after 7.3.2
Fix from $1,600 2019-07-17
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2018-2021

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Fix: 7.2.8+
Fix from $1,600 2019-07-17
Campaign MEDIUM 5.4
CVE-2018-1921

IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2019-07-17
Planning Analytics MEDIUM 6.1
CVE-2019-4134

IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2019-07-02
Business Automation Workflow MEDIUM 5.4
CVE-2019-4410

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to…

Fix: after 19.0.0.1
Fix from $1,600 2019-07-01
Infosphere Information Server MEDIUM 5.4
CVE-2019-4237

A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable applicat…

Mitigation only
Fix from $1,600 2019-07-01
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1760

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1826

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1827

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1828

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1892

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1893

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2019-4083

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulner…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2019-4249

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2019-4250

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulner…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2018-1758

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: after 6.0.6.1
Fix from $1,600 2019-06-27
Security Access Manager MEDIUM 6.1
CVE-2019-4157

IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Fix: after 9.0.6
Fix from $1,600 2019-06-25
Maximo Asset Management MEDIUM 5.4
CVE-2019-4303

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Mitigation only
Fix from $1,600 2019-06-19
Cognos Controller MEDIUM 5.4
CVE-2019-4136

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi…

Patch available
Fix from $1,600 2019-06-17
Connections MEDIUM 5.4
CVE-2019-4403

IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2019-06-14
Intelligent Operations Center MEDIUM 5.4
CVE-2019-4070

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 5.2.1.1
Fix from $1,600 2019-06-07
Spectrum Control MEDIUM 6.1
CVE-2019-4137

IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra…

Fix: after 5.3.2.0
Fix from $1,600 2019-05-29
Cognos Analytics MEDIUM 5.4
CVE-2019-4139

IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2019-05-29