Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Jazz Reporting Service MEDIUM 5.4
CVE-2016-5897

IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exe…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-5899

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lcms Premier MEDIUM 5.4
CVE-2016-5948

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Kenexa Lcms Premier MEDIUM 5.4
CVE-2016-5951

IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Tririga Application Platform MEDIUM 5.4
CVE-2016-5980

IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-6030

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Patch available
Fix from $1,600 2017-02-01
Jazz Reporting Service MEDIUM 5.4
CVE-2016-6039

IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

Patch available
Fix from $1,600 2017-02-01
Tivoli Storage Manager MEDIUM 5.4
CVE-2016-6046

IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-2938

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-2939

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Security Access Manager MEDIUM 6.1
CVE-2016-3018

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mitigation only
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-5882

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 6.1
CVE-2016-5884

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Campaign MEDIUM 5.4
CVE-2016-0265

IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulner…

Patch available
Fix from $1,600 2017-02-01
Domino MEDIUM 5.4
CVE-2016-5880

IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …

Patch available
Fix from $1,600 2017-02-01
Urbancode Deploy MEDIUM 5.4
CVE-2016-2994

Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2016-12-01
Lotus Protector For Mail Security MEDIUM 5.4
CVE-2016-2991

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remot…

Mitigation only
Fix from $1,600 2016-12-01
Connections MEDIUM 5.4
CVE-2016-2955

Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary w…

Patch available
Fix from $1,600 2016-12-01
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2016-2869

Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authentica…

Fix: after 7.1.0
Fix from $1,600 2016-11-30
Maximo Asset Management MEDIUM 5.4
CVE-2016-5905

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticate…

Patch available
Fix from $1,600 2016-11-30
Sterling B2b Integrator MEDIUM 6.1
CVE-2016-3057

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to …

Patch available
Fix from $1,600 2016-11-30
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-3014

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rati…

Mitigation only
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.1
CVE-2016-2934

Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Rational Team Concert MEDIUM 5.4
CVE-2016-2926

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0316

Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 b…

Patch available
Fix from $1,600 2016-11-25
Filenet Workplace MEDIUM 5.4
CVE-2016-5981

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine) through 4.…

Fix: after 4.0.2.14-p8ae-if001
Fix from $1,600 2016-11-25
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-5955

Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbit…

Mitigation only
Fix from $1,600 2016-11-25
Rational Engineering Lifecycle Manager MEDIUM 5.4
CVE-2016-2986

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x befo…

Mitigation only
Fix from $1,600 2016-11-25
Rational Quality Manager MEDIUM 5.4
CVE-2016-2864

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Rational Team Concert MEDIUM 5.4
CVE-2016-0285

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24