Ibm Infosphere Master Data Management vulnerabilities

26 known vulnerabilities affecting ibm/infosphere_master_data_management.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM17LOW4

Vulnerabilities

Page 1 of 2
CVE-2023-46187MEDIUMCVSS 5.4v11.6v12.0+2 more2025-01-27
CVE-2023-46187 [MEDIUM] CWE-79 CVE-2023-46187: IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site script IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2020-4675MEDIUMCVSS 6.5v11.62021-07-16
CVE-2020-4675 [MEDIUM] CWE-352 CVE-2020-4675: IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
cvelistv5nvd
CVE-2018-1380MEDIUMCVSS 4.9v11.4v11.5+1 more2018-10-29
CVE-2018-1380 [LOW] CWE-200 CVE-2018-1380: IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authe IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.
nvd
CVE-2015-7424MEDIUMCVSS 4.3v9.1v10.1+4 more2018-03-26
CVE-2015-7424 [MEDIUM] CWE-200 CVE-2015-7424: IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.
nvd
CVE-2015-7423MEDIUMCVSS 5.4v9.1v10.1+3 more2018-03-26
CVE-2015-7423 [MEDIUM] CWE-79 CVE-2015-7423: Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.
nvd
CVE-2017-1523HIGHCVSS 7.5v11.52017-10-24
CVE-2017-1523 [HIGH] CWE-306 CVE-2017-1523: IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
nvd
CVE-2017-1199MEDIUMCVSS 5.4v10.1v11.0+6 more2017-08-03
CVE-2017-1199 [MEDIUM] CWE-79 CVE-2017-1199: IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.
cvelistv5nvd
CVE-2016-9716HIGHCVSS 8.8v11.0v11.3+4 more2017-07-31
CVE-2016-9716 [HIGH] CWE-352 CVE-2016-9716: IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.
cvelistv5nvd
CVE-2016-9714HIGHCVSS 8.8v10.1v11.0+6 more2017-07-31
CVE-2016-9714 [HIGH] CWE-352 CVE-2016-9714: IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.
cvelistv5nvd
CVE-2016-9718MEDIUMCVSS 5.4v10.1v11.0+6 more2017-07-31
CVE-2016-9718 [MEDIUM] CWE-79 CVE-2016-9718: IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.
cvelistv5nvd
CVE-2016-9715MEDIUMCVSS 5.4v11.0v11.3+4 more2017-07-31
CVE-2016-9715 [MEDIUM] CWE-79 CVE-2016-9715: IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.
cvelistv5nvd
CVE-2016-9717MEDIUMCVSS 6.5v10.1v11.0+6 more2017-07-31
CVE-2016-9717 [MEDIUM] CWE-20 CVE-2016-9717: HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
cvelistv5nvd
CVE-2016-9719MEDIUMCVSS 5.7v10.1v11.0+6 more2017-07-31
CVE-2016-9719 [MEDIUM] CWE-20 CVE-2016-9719: IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a re IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victi
cvelistv5nvd
CVE-2017-1309HIGHCVSS 7.8v11.0v11.3+3 more2017-07-19
CVE-2017-1309 [HIGH] CWE-312 CVE-2017-1309: IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear t IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
cvelistv5nvd
CVE-2015-4960MEDIUMCVSS 4.1v9.1v10.1+3 more2016-01-17
CVE-2015-4960 [MEDIUM] CWE-254 CVE-2015-4960: IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
nvd
CVE-2015-7414MEDIUMCVSS 5.4v9.1v10.1+3 more2016-01-17
CVE-2015-7414 [MEDIUM] CWE-79 CVE-2015-7414: Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Manageme Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-4958LOWCVSS 3.3v9.1v10.1+3 more2016-01-17
CVE-2015-4958 [LOW] CWE-200 CVE-2015-4958: IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.
nvd
CVE-2015-1984MEDIUMCVSS 4.0v9.1v10.1+3 more2015-07-20
CVE-2015-1984 [MEDIUM] CWE-200 CVE-2015-1984: IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before F IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
nvd
CVE-2015-1982MEDIUMCVSS 4.0v9.1v10.1+3 more2015-07-20
CVE-2015-1982 [MEDIUM] CWE-200 CVE-2015-1982: IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before F IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.
nvd
CVE-2015-1980LOWCVSS 3.5v9.1v10.1+3 more2015-07-20
CVE-2015-1980 [LOW] CWE-20 CVE-2015-1980: IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before F IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
nvd