Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Infosphere Information Server MEDIUM 5.4
CVE-2022-30615

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Infosphere Information Server MEDIUM 5.4
CVE-2022-35642

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Patch available
Fix from $1,600 2022-11-03
Robotic Process Automation For Cloud Pak MEDIUM 6.1
CVE-2022-38709

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to emb…

Fix: 21.0.4+
Fix from $1,600 2022-10-06
Rational Change MEDIUM 6.1
CVE-2012-2160

IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit …

Patch available
Fix from $1,600 2022-09-29
Jazz For Service Management MEDIUM 5.4
CVE-2022-35722

IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Fix: 1.1.3.16+
Fix from $1,600 2022-09-28
Application Gateway MEDIUM 5.4
CVE-2022-22387

IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Patch available
Fix from $1,600 2022-09-28
Infosphere Information Server MEDIUM 5.4
CVE-2022-40748

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Mitigation only
Fix from $1,600 2022-09-23
Jazz For Service Management MEDIUM 5.4
CVE-2022-35721

IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2022-09-23
Websphere Application Server MEDIUM 5.4
CVE-2022-34336

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav…

Patch available
Fix from $1,600 2022-09-13
Engineering Test Management MEDIUM 5.4
CVE-2021-38934

IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS…

Mitigation only
Fix from $1,600 2022-08-29
Maximo Asset Management MEDIUM 5.4
CVE-2022-35714

IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

Patch available
Fix from $1,600 2022-08-26
Sterling B2b Integrator MEDIUM 5.4
CVE-2021-39035

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-sit…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Cics Tx MEDIUM 6.1
CVE-2022-34163

IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to …

Patch available
Fix from $1,600 2022-08-01
Datapower Gateway MEDIUM 5.4
CVE-2022-31774

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site …

Fix: 10.5.0.1+
Fix from $1,600 2022-08-01
Datapower Gateway MEDIUM 5.4
CVE-2022-32750

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site …

Fix: 10.5.0.1+
Fix from $1,600 2022-08-01
Partner Engagement Manager MEDIUM 5.4
CVE-2022-22417

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to emb…

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,600 2022-07-19
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2021-29788

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…

Mitigation only
Fix from $1,600 2022-07-18
Engineering Requirements Quality Assistant On Premises MEDIUM 5.4
CVE-2021-29790

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to e…

Mitigation only
Fix from $1,600 2022-07-18
Websphere Application Server MEDIUM 6.1
CVE-2022-22477

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

Patch available
Fix from $1,600 2022-07-14
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2021-39015

IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to e…

Patch available
Fix from $1,600 2022-07-14
I MEDIUM 5.4
CVE-2022-34358

IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Patch available
Fix from $1,600 2022-07-13
Security Verify Access MEDIUM 5.4
CVE-2022-22370

IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34160

IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would …

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34166

IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34167

IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…

Patch available
Fix from $1,600 2022-07-08
Cics Tx MEDIUM 5.4
CVE-2022-34306

IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could…

Patch available
Fix from $1,600 2022-07-08
Security Guardium MEDIUM 6.1
CVE-2021-39074

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

Mitigation only
Fix from $1,600 2022-06-29
Jazz Team Server MEDIUM 5.4
CVE-2021-20543

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.4
CVE-2021-38871

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary …

Patch available
Fix from $1,600 2022-06-24
Robotic Process Automation MEDIUM 5.4
CVE-2022-22502

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript…

Fix: 21.0.1.5 / 21.0.2.2+
Fix from $1,600 2022-06-24