Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Connections MEDIUM 5.4
CVE-2016-0310

IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

Patch available
Fix from $1,600 2017-02-08
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6032

IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Patch available
Fix from $1,600 2017-02-08
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1127

IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Patch available
Fix from $1,600 2017-02-08
Rational Doors Next Generation MEDIUM 5.4
CVE-2017-1128

IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2017-02-08
Security Key Lifecycle Manager MEDIUM 6.1
CVE-2016-6096

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Patch available
Fix from $1,600 2017-02-07
Infosphere Datastage MEDIUM 6.1
CVE-2016-9000

IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this …

Patch available
Fix from $1,600 2017-02-01
Security Identity Manager Virtual Appliance MEDIUM 6.1
CVE-2016-9704

IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Patch available
Fix from $1,600 2017-02-01
Infosphere Datastage MEDIUM 5.4
CVE-2016-8999

IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode ther…

Patch available
Fix from $1,600 2017-02-01
Inotes MEDIUM 6.1
CVE-2016-5881

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Mitigation only
Fix from $1,600 2017-02-01
Cognos Analytics MEDIUM 5.4
CVE-2016-0217

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-suppli…

Patch available
Fix from $1,600 2017-02-01
Cognos Business Intelligence MEDIUM 5.4
CVE-2016-0218

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied inpu…

Patch available
Fix from $1,600 2017-02-01
Biginsights MEDIUM 5.4
CVE-2016-2924

IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could explo…

Patch available
Fix from $1,600 2017-02-01
Biginsights MEDIUM 5.4
CVE-2016-2992

IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-5940

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms MEDIUM 5.4
CVE-2016-5942

IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2017-02-01
Spectrum Control MEDIUM 5.4
CVE-2016-8943

IBM Tivoli Storage Productivity Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2017-02-01
Business Process Manager MEDIUM 5.4
CVE-2016-9731

IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-6113

IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

Mitigation only
Fix from $1,600 2017-02-01
Web Content Manager Production Analytics MEDIUM 6.1
CVE-2016-8922

Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

Mitigation only
Fix from $1,600 2017-02-01
Social Rendering Templates For Digital Data Connector MEDIUM 6.1
CVE-2016-8936

IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6047

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6054

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6061

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Maximo Asset Management MEDIUM 5.4
CVE-2016-6072

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6123

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-6125

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Kenexa Lms On Cloud MEDIUM 5.4
CVE-2016-8920

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

Mitigation only
Fix from $1,600 2017-02-01
Websphere Application Server MEDIUM 5.4
CVE-2016-8934

IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Infosphere Information Server MEDIUM 6.1
CVE-2016-5984

IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could expl…

Patch available
Fix from $1,600 2017-02-01
Tririga Application Platform MEDIUM 6.1
CVE-2016-6000

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01