Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Rational Quality Manager MEDIUM 5.4
CVE-2017-1277

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Quality Manager MEDIUM 5.4
CVE-2017-1280

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Quality Manager MEDIUM 5.4
CVE-2017-1281

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Quality Manager MEDIUM 5.4
CVE-2017-1293

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Quality Manager MEDIUM 5.4
CVE-2017-1294

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Quality Manager MEDIUM 5.4
CVE-2017-1299

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1306

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1312

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1313

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1314

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1315

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2017-1316

IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…

Mitigation only
Fix from $1,600 2018-07-03
Rational Doors Next Generation MEDIUM 5.4
CVE-2018-1507

IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2018-06-27
Content Navigator MEDIUM 5.4
CVE-2018-1496

IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Patch available
Fix from $1,600 2018-05-31
Security Guardium Big Data Intelligence MEDIUM 6.1
CVE-2018-1376

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja…

Patch available
Fix from $1,600 2018-05-29
Storwize V7000 Firmware MEDIUM 5.4
CVE-2018-1461

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Cognos Analytics MEDIUM 5.4
CVE-2018-1413

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Fix: after 11.0.10.0
Fix from $1,600 2018-05-07
Content Manager MEDIUM 5.4
CVE-2018-1502

IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Patch available
Fix from $1,600 2018-05-01
Api Connect MEDIUM 5.4
CVE-2018-1430

IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Fix: after 5.0.8.2
Fix from $1,600 2018-04-30
Bigfix Platform MEDIUM 6.1
CVE-2018-1473

IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Fix: after 9.5.8
Fix from $1,600 2018-04-27
Qradar Security Information And Event Manager MEDIUM 6.1
CVE-2017-1724

IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: 7.2.8+
Fix from $1,600 2018-04-26
Jazz Reporting Service MEDIUM 5.4
CVE-2017-1750

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Patch available
Fix from $1,600 2018-04-25
Jazz Reporting Service MEDIUM 5.4
CVE-2018-1363

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to em…

Patch available
Fix from $1,600 2018-04-25
Cognos Business Intelligence MEDIUM 6.1
CVE-2017-1486

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Mitigation only
Fix from $1,600 2018-04-23
Power Hardware Management Console MEDIUM 6.1
CVE-2014-0883

IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Mitigation only
Fix from $1,600 2018-04-20
Websphere Portal MEDIUM 5.4
CVE-2018-1445

IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja…

Fix: after 8.0.0.1
Fix from $1,600 2018-04-17
Security Appscan MEDIUM 5.4
CVE-2015-1952

Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary we…

Patch available
Fix from $1,600 2018-04-16
Forms Experience Builder MEDIUM 5.4
CVE-2014-6169

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HT…

Mitigation only
Fix from $1,600 2018-04-12
Rational Requirements Composer MEDIUM 5.4
CVE-2017-1790

IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users t…

Patch available
Fix from $1,600 2018-04-12
Websphere Portal MEDIUM 6.1
CVE-2018-1483

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2018-04-11