Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Jazz Reporting Service MEDIUM 5.4
CVE-2016-2888

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0350

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
Jazz Reporting Service MEDIUM 5.4
CVE-2016-0313

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0…

Mitigation only
Fix from $1,600 2016-07-08
Websphere Commerce MEDIUM 6.1
CVE-2016-2862

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5…

Patch available
Fix from $1,600 2016-07-03
Cognos Business Intelligence MEDIUM 5.4
CVE-2016-0346

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 befor…

Mitigation only
Fix from $1,600 2016-07-03
Cognos Business Intelligence MEDIUM 5.4
CVE-2016-0221

Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.…

Mitigation only
Fix from $1,600 2016-07-03
Tririga Application Platform MEDIUM 5.4
CVE-2016-2883

Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows re…

Patch available
Fix from $1,600 2016-07-02
Maximo Asset Management MEDIUM 5.4
CVE-2016-0399

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP00…

Mitigation only
Fix from $1,600 2016-07-02
Tririga Application Platform MEDIUM 5.4
CVE-2016-0387

Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows re…

Patch available
Fix from $1,600 2016-07-02
Connections MEDIUM 5.4
CVE-2016-0322

Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authe…

Mitigation only
Fix from $1,600 2016-06-30
Marketing Platform MEDIUM 6.1
CVE-2016-0229

Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2016-06-28
Algo One MEDIUM 5.4
CVE-2016-0390

Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated use…

Mitigation only
Fix from $1,600 2016-05-15
Websphere Application Server MEDIUM 6.1
CVE-2016-0283

Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profil…

Mitigation only
Fix from $1,600 2016-03-19
Maximo Asset Management MEDIUM 5.4
CVE-2016-0262

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3…

Mitigation only
Fix from $1,600 2016-03-14
Business Process Manager MEDIUM 5.4
CVE-2016-0227

Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0…

Mitigation only
Fix from $1,600 2016-03-03
Websphere Portal MEDIUM 6.1
CVE-2016-0244

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29…

Mitigation only
Fix from $1,600 2016-02-29
Websphere Portal MEDIUM 6.1
CVE-2016-0243

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29…

Mitigation only
Fix from $1,600 2016-02-29
Business Process Manager MEDIUM 6.1
CVE-2015-8524

Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.…

Mitigation only
Fix from $1,600 2016-02-29
Websphere Portal MEDIUM 6.1
CVE-2015-7457

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to i…

Mitigation only
Fix from $1,600 2016-02-29
Websphere Portal MEDIUM 5.4
CVE-2015-7491

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated …

Mitigation only
Fix from $1,600 2016-02-29
Security Access Manager 9.0 Firmware MEDIUM 6.1
CVE-2015-8531

Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attac…

Mitigation only
Fix from $1,600 2016-02-15
Infosphere Master Data Management Reference Data Management MEDIUM 5.4
CVE-2015-7492

Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.…

Mitigation only
Fix from $1,600 2016-02-15
Emptoris Contract Management MEDIUM 5.4
CVE-2015-7398

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFi…

Mitigation only
Fix from $1,600 2016-02-15
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2015-4957

Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to…

Mitigation only
Fix from $1,600 2016-02-15
Websphere Portal MEDIUM 6.1
CVE-2016-0209

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via…

Mitigation only
Fix from $1,600 2016-01-27
Rational Software Architect Realtime MEDIUM 6.1
CVE-2015-7439

Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Architect 8.5 through 9.5, Ratio…

Mitigation only
Fix from $1,600 2016-01-27
Websphere Application Server MEDIUM 5.4
CVE-2015-7417

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows …

Mitigation only
Fix from $1,600 2016-01-23
Websphere Commerce MEDIUM 5.4
CVE-2015-5009

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through …

Patch available
Fix from $1,600 2016-01-18
Websphere Commerce MEDIUM 6.1
CVE-2015-5008

Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through …

Mitigation only
Fix from $1,600 2016-01-18
Host On Demand MEDIUM 6.1
CVE-2015-5002

Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML vi…

Mitigation only
Fix from $1,600 2016-01-18