Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Content Navigator MEDIUM 5.4
CVE-2017-1331

IBM Content Navigator 2.0.3 and 3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Patch available
Fix from $1,600 2017-08-04
Inotes MEDIUM 6.1
CVE-2017-1327

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Patch available
Fix from $1,600 2017-08-03
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2017-1199

IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows …

Patch available
Fix from $1,600 2017-08-03
Mobilefirst Platform Foundation MEDIUM 6.1
CVE-2017-1500

A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, …

Mitigation only
Fix from $1,600 2017-08-01
Websphere Portal MEDIUM 6.1
CVE-2017-1303

IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Patch available
Fix from $1,600 2017-07-31
Inotes MEDIUM 6.1
CVE-2017-1332

IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…

Mitigation only
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2016-9715

IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users …

Patch available
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.4
CVE-2016-9718

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows …

Patch available
Fix from $1,600 2017-07-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2017-1496

IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Mitigation only
Fix from $1,600 2017-07-31
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-6118

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Patch available
Fix from $1,600 2017-07-24
Rhapsody Design Manager MEDIUM 5.4
CVE-2016-8975

IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Patch available
Fix from $1,600 2017-07-24
Rational Software Architect Design Manager MEDIUM 5.4
CVE-2017-1245

IBM Rational Software Architect Design Manager 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2017-07-24
Rhapsody Design Manager MEDIUM 5.4
CVE-2017-1249

IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Patch available
Fix from $1,600 2017-07-24
Websphere Application Server MEDIUM 5.4
CVE-2017-1380

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Fix: after 9.0.0.4
Fix from $1,600 2017-07-24
Tririga Application Platform MEDIUM 5.4
CVE-2017-1372

IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

Patch available
Fix from $1,600 2017-07-21
Bigfix Platform MEDIUM 6.1
CVE-2017-1203

IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting. This vulnerability allows us…

Mitigation only
Fix from $1,600 2017-07-19
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-6019

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to…

Patch available
Fix from $1,600 2017-07-13
Emptoris Strategic Supply Management MEDIUM 5.4
CVE-2016-8952

IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to…

Patch available
Fix from $1,600 2017-07-13
Infosphere Information Server MEDIUM 6.1
CVE-2017-1321

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Patch available
Fix from $1,600 2017-07-12
Emptoris Sourcing MEDIUM 5.4
CVE-2016-6114

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2017-07-12
Emptoris Sourcing MEDIUM 5.4
CVE-2016-8946

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2017-07-12
Emptoris Sourcing MEDIUM 5.4
CVE-2016-8948

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Patch available
Fix from $1,600 2017-07-12
Emptoris Sourcing MEDIUM 5.4
CVE-2016-8950

IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2017-07-12
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9986

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9987

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9988

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2016-9989

IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Mitigation only
Fix from $1,600 2017-07-05
Jazz Reporting Service MEDIUM 5.4
CVE-2017-1096

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2016-9701

IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Mitigation only
Fix from $1,600 2017-07-05
Rational Team Concert MEDIUM 5.4
CVE-2016-9733

IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Mitigation only
Fix from $1,600 2017-07-05