Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Cloud Pak For Data MEDIUM 6.1
CVE-2025-0719

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to …

Fix: after 4.8.5
Fix from $1,600 2025-02-26
Openpages With Watson MEDIUM 5.4
CVE-2024-49337

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of te…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Cognos Controller MEDIUM 5.4
CVE-2024-28776

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Jazz For Service Management MEDIUM 6.1
CVE-2024-52892

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker t…

Fix: 1.1.3.24+
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49791

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49792

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Applinx MEDIUM 5.4
CVE-2024-49793

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web…

Mitigation only
Fix from $1,600 2025-02-06
Aspera Shares MEDIUM 5.4
CVE-2024-56472

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbi…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Aspera Shares MEDIUM 6.1
CVE-2024-38318

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, wo…

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52364

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2024-52365

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Mitigation only
Fix from $1,600 2025-02-05
Security Verify Access MEDIUM 6.1
CVE-2024-40700

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthen…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2024-49339

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vu…

Fix: after 3.2.4.13
Fix from $1,600 2025-01-31
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2024-49349

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vu…

Fix: after 3.2.4.13
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-47103

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-47116

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-49807

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-40696

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-31
Openpages With Watson MEDIUM 5.4
CVE-2024-37527

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaS…

Fix: 8.3.0.3 / 9.0.0.4+
Fix from $1,600 2025-01-27
Sterling File Gateway MEDIUM 5.4
CVE-2023-52292

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows…

Fix: after 6.2.0.3
Fix from $1,600 2025-01-27
Infosphere Master Data Management MEDIUM 5.4
CVE-2023-46187

IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arb…

Mitigation only
Fix from $1,600 2025-01-27
Maximo Application Suite MEDIUM 6.1
CVE-2024-35145

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker t…

Mitigation only
Fix from $1,600 2025-01-25
Tivoli Application Dependency Discovery Manager MEDIUM 5.4
CVE-2025-23227

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows …

Fix: after 7.3.0.11
Fix from $1,600 2025-01-23
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-32340

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Fix: after 6.1.2.5
Fix from $1,600 2025-01-23
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-50309

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embe…

Fix: after 6.1.2.5
Fix from $1,600 2025-01-23
Robotic Process Automation For Cloud Pak MEDIUM 5.4
CVE-2024-51457

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerab…

Fix: 21.0.7.20 / 23.0.20+
Fix from $1,600 2025-01-22
Cics Tx MEDIUM 6.1
CVE-2024-41746

IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-16
Jazz Foundation MEDIUM 5.4
CVE-2021-29669

IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Mitigation only
Fix from $1,600 2025-01-12
Watsonx.ai MEDIUM 5.4
CVE-2024-49785

IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability…

Fix: 2.1.0 / 5.1.0+
Fix from $1,600 2025-01-12
Sterling B2b Integrator MEDIUM 6.4
CVE-2024-31914

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This v…

Fix: after 6.2.0.2
Fix from $1,600 2025-01-06