Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Lotus Inotes MEDIUM 5.4
CVE-2016-0282

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2016-11-24
Rational Doors Next Generation MEDIUM 5.4
CVE-2016-0273

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before…

Mitigation only
Fix from $1,600 2016-11-24
Financial Transaction Manager MEDIUM 5.4
CVE-2016-5920

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 …

Patch available
Fix from $1,600 2016-10-29
Security Guardium MEDIUM 6.1
CVE-2016-0246

Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 all…

Patch available
Fix from $1,600 2016-10-22
Business Process Manager MEDIUM 5.4
CVE-2016-3056

Cross-site scripting (XSS) vulnerability in Business Space in IBM Business Process Manager 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, and 8.5 before 8…

Patch available
Fix from $1,600 2016-10-14
Sterling Secure Proxy MEDIUM 6.1
CVE-2016-6027

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS pro…

Mitigation only
Fix from $1,600 2016-10-06
Business Process Manager MEDIUM 5.4
CVE-2016-5901

Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.0…

Patch available
Fix from $1,600 2016-10-05
Multi Enterprise Integration Gateway MEDIUM 5.4
CVE-2016-5892

Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communicati…

Fix: after 1.0.0.5_1
Fix from $1,600 2016-10-05
Websphere Application Server MEDIUM 5.4
CVE-2016-3042

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated …

Mitigation only
Fix from $1,600 2016-10-01
Tealeaf Customer Experience MEDIUM 5.4
CVE-2016-5978

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.…

Mitigation only
Fix from $1,600 2016-09-26
Tealeaf Customer Experience MEDIUM 5.4
CVE-2016-5975

Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.…

Fix: after 8.7
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 5.4
CVE-2016-5974

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 all…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 5.4
CVE-2016-5944

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allo…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3006

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3003

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 5.4
CVE-2016-3001

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authe…

Patch available
Fix from $1,600 2016-09-26
Rational Collaborative Lifecycle Management MEDIUM 5.4
CVE-2016-0331

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Managem…

Patch available
Fix from $1,600 2016-09-12
Connections MEDIUM 5.4
CVE-2016-3010

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-3008

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-3005

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2997

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2995

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2956

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Connections MEDIUM 5.4
CVE-2016-2954

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inje…

Patch available
Fix from $1,600 2016-09-01
Bigfix Platform MEDIUM 6.1
CVE-2016-0293

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows rem…

Mitigation only
Fix from $1,600 2016-09-01
Filenet Workplace MEDIUM 5.4
CVE-2016-3054

Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by u…

Patch available
Fix from $1,600 2016-08-08
Websphere Portal MEDIUM 5.4
CVE-2016-2925

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30…

Mitigation only
Fix from $1,600 2016-08-08
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2912

Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote aut…

Mitigation only
Fix from $1,600 2016-08-08
Information Server Framework MEDIUM 5.4
CVE-2016-0280

Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Busi…

Patch available
Fix from $1,600 2016-08-08
Bigfix Platform MEDIUM 5.4
CVE-2016-0269

Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject a…

Mitigation only
Fix from $1,600 2016-07-15