Show filters
45 Total Results
Displaying 1-10 of 45
Sort by:
Attacker Value
Unknown
CVE-2023-46187
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2020-4675
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
0
Attacker Value
Unknown
CVE-2018-1380
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.
0
Attacker Value
Unknown
CVE-2015-7423
Disclosure Date: March 26, 2018 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.
0
Attacker Value
Unknown
CVE-2015-7424
Disclosure Date: March 26, 2018 (last updated November 26, 2024)
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.
0
Attacker Value
Unknown
CVE-2017-1523
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
0
Attacker Value
Unknown
CVE-2017-1199
Disclosure Date: August 03, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.
0
Attacker Value
Unknown
CVE-2016-9719
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 119733.
0
Attacker Value
Unknown
CVE-2016-9714
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.
0
Attacker Value
Unknown
CVE-2016-9717
Disclosure Date: July 31, 2017 (last updated November 26, 2024)
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
0