Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Aspera Faspex MEDIUM 5.4
CVE-2023-37411

IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

Fix: after 5.0.6
Fix from $1,600 2024-05-28
Engineering Workflow Management MEDIUM 5.4
CVE-2024-28793

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability al…

Mitigation only
Fix from $1,600 2024-05-28
Security Guardium MEDIUM 5.4
CVE-2023-47710

IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Mitigation only
Fix from $1,600 2024-05-24
App Connect Enterprise MEDIUM 5.4
CVE-2024-28761

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject …

Fix: 11.0.0.26 / 12.0.12.1+
Fix from $1,600 2024-05-14
Devops Deploy MEDIUM 5.4
CVE-2024-28781

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerabl…

Fix: 7.0.5.21 / 7.1.2.17+
Fix from $1,600 2024-05-14
Txseries For Multiplatform MEDIUM 6.1
CVE-2024-22344

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Mitigation only
Fix from $1,600 2024-05-14
Websphere Automation MEDIUM 5.4
CVE-2024-28775

IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Mitigation only
Fix from $1,600 2024-05-01
Cloud Pak For Security MEDIUM 5.4
CVE-2023-47731

IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site sc…

Fix: after 1.10.19.0
Fix from $1,600 2024-04-23
Devops Deploy MEDIUM 6.1
CVE-2024-22359

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.…

Fix: 7.0.5.21 / 7.1.2.17+
Fix from $1,600 2024-04-12
Sterling File Gateway MEDIUM 5.4
CVE-2023-47714

IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability all…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-45186

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Sterling B2b Integrator MEDIUM 5.4
CVE-2023-50307

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Sterling B2b Integrator MEDIUM 5.4
CVE-2024-22357

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability a…

Fix: after 6.1.2.3
Fix from $1,600 2024-04-12
Websphere Application Server MEDIUM 6.1
CVE-2024-27270

IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar…

Fix: 24.0.0.4+
Fix from $1,600 2024-03-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2024-28784

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

Mitigation only
Fix from $1,600 2024-03-27
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2023-50961

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2024-03-27
Sterling Secure Proxy MEDIUM 6.1
CVE-2023-47699

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 6.1
CVE-2023-47162

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Patch available
Fix from $1,600 2024-03-15
Sterling Secure Proxy MEDIUM 5.4
CVE-2023-46182

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2024-03-15
Maximo Application Suite MEDIUM 6.4
CVE-2023-38723

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

Mitigation only
Fix from $1,600 2024-03-13
Sterling Partner Engagement Manager MEDIUM 5.4
CVE-2023-28517

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit…

Mitigation only
Fix from $1,600 2024-03-13
Cics Tx MEDIUM 6.1
CVE-2023-38360

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…

Mitigation only
Fix from $1,600 2024-03-04
Engineering Test Management MEDIUM 5.4
CVE-2023-43054

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary Java…

Mitigation only
Fix from $1,600 2024-03-03
Infosphere Information Server MEDIUM 6.1
CVE-2023-50303

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-28
Infosphere Information Server MEDIUM 5.4
CVE-2023-33843

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2024-02-21
Business Automation Workflow MEDIUM 5.4
CVE-2023-50947

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…

Fix: after 21.0.3.1
Fix from $1,600 2024-02-04
Tivoli Application Dependency Discovery Manager MEDIUM 6.1
CVE-2023-47144

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users t…

Fix: 7.3.0.11+
Fix from $1,600 2024-02-02
Aspera Faspex MEDIUM 5.4
CVE-2022-40744

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…

Fix: 5.0.7+
Fix from $1,600 2024-02-02
Powersc MEDIUM 6.1
CVE-2023-50933

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be execut…

Patch available
Fix from $1,600 2024-02-02
Aspera Console MEDIUM 6.1
CVE-2021-38927

IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…

Fix: 3.4.2+
Fix from $1,600 2023-12-25