Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Cognos Analytics MEDIUM 6.1
CVE-2021-39036

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

Mitigation only
Fix from $1,600 2023-05-12
Business Automation Workflow MEDIUM 5.4
CVE-2023-24957

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 i…

Fix: 21.0.3 / 22.0.2+
Fix from $1,600 2023-05-06
Maximo Asset Management MEDIUM 5.4
CVE-2022-43866

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Mitigation only
Fix from $1,600 2023-05-05
I MEDIUM 6.4
CVE-2023-23470

IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a re…

Mitigation only
Fix from $1,600 2023-05-04
Financial Transaction Manager For Multiplatform MEDIUM 5.4
CVE-2022-43871

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Mitigation only
Fix from $1,600 2023-04-29
Maximo Asset Management MEDIUM 5.4
CVE-2023-27864

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewe…

Patch available
Fix from $1,600 2023-04-28
Websphere Application Server MEDIUM 6.1
CVE-2023-24966

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,600 2023-04-27
Tririga Application Platform MEDIUM 5.4
CVE-2022-43914

IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Fix: 4.0.3+
Fix from $1,600 2023-04-07
Websphere Application Server MEDIUM 5.4
CVE-2023-26283

IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the…

Patch available
Fix from $1,600 2023-04-02
App Connect Enterprise Certified Container MEDIUM 6.1
CVE-2022-43874

IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerabil…

Mitigation only
Fix from $1,600 2023-03-15
Maximo Application Suite MEDIUM 5.4
CVE-2022-35645

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This…

Patch available
Fix from $1,600 2023-03-02
Cloud Pak For Business Automation MEDIUM 5.4
CVE-2023-22860

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.…

Patch available
Fix from $1,600 2023-02-27
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-43578

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.1.2.0
Fix from $1,600 2023-02-22
Infosphere Information Server MEDIUM 5.4
CVE-2023-25928

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2023-02-21
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-43579

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-site scripting. This vulnerab…

Fix: after 6.1.2.0
Fix from $1,600 2023-02-17
Aspera Faspex MEDIUM 5.4
CVE-2023-22868

IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Fix: after 4.4.1
Fix from $1,600 2023-02-17
Infosphere Information Server MEDIUM 5.4
CVE-2022-47983

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2023-02-01
Robotic Process Automation MEDIUM 5.4
CVE-2023-22594

IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed a…

Fix: 21.0.5+
Fix from $1,600 2023-01-18
Sterling B2b Integrator MEDIUM 6.1
CVE-2022-34330

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: after 6.1.1.2
Fix from $1,600 2023-01-05
Sterling B2b Integrator MEDIUM 5.4
CVE-2022-22352

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed …

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Security Verify Governance MEDIUM 6.1
CVE-2022-22456

IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Patch available
Fix from $1,600 2022-12-22
Cognos Analytics MEDIUM 6.1
CVE-2022-39160

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Fix: 11.1.7+
Fix from $1,600 2022-12-19
Transformation Advisor MEDIUM 5.4
CVE-2022-41299

IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc…

Fix: 3.4.0+
Fix from $1,600 2022-12-09
Business Automation Workflow MEDIUM 6.1
CVE-2022-41735

IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This…

Fix: after 21.0.3.1
Fix from $1,600 2022-12-07
Business Automation Workflow MEDIUM 5.4
CVE-2022-38390

Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr…

Fix: after 21.0.3.1
Fix from $1,600 2022-11-17
Infosphere Information Server MEDIUM 5.4
CVE-2022-40753

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2022-11-15
Cics Tx MEDIUM 5.4
CVE-2022-34317

IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…

Patch available
Fix from $1,600 2022-11-14
Cics Tx MEDIUM 5.4
CVE-2022-34315

IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…

Patch available
Fix from $1,600 2022-11-14
Websphere Application Server MEDIUM 5.4
CVE-2022-40750

IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2022-11-11
Cloud Pak For Security MEDIUM 5.4
CVE-2022-36776

IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J…

Fix: after 1.10.2.0
Fix from $1,600 2022-11-11