Ibm Infosphere Master Data Management vulnerabilities
26 known vulnerabilities affecting ibm/infosphere_master_data_management.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM17LOW4
Vulnerabilities
Page 1 of 2
CVE-2017-1523P3HIGHCVSS 7.5v11.52017-10-24
CVE-2017-1523 [HIGH] CWE-306 CVE-2017-1523: IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
nvd
CVE-2016-9716P3HIGHCVSS 8.8v11.0v11.3+4 more2017-07-31
CVE-2016-9716 [HIGH] CWE-352 CVE-2016-9716: IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.
nvd
CVE-2016-9714P3HIGHCVSS 8.8v10.1v11.0+6 more2017-07-31
CVE-2016-9714 [HIGH] CWE-352 CVE-2016-9714: IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.
nvd
CVE-2014-0966P3MEDIUMCVSS 6.5v10.0v10.1+2 more2014-08-17
CVE-2014-0966 [MEDIUM] CWE-89 CVE-2014-0966: SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collabor
SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2017-1309P4HIGHCVSS 7.8v11.0v11.3+3 more2017-07-19
CVE-2017-1309 [HIGH] CWE-312 CVE-2017-1309: IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear t
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
nvd
CVE-2016-9717P4MEDIUMCVSS 6.5v10.1v11.0+6 more2017-07-31
CVE-2016-9717 [MEDIUM] CWE-20 CVE-2016-9717: HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0.
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
nvd
CVE-2014-3063P4HIGHCVSS 7.5v10.0v10.1+2 more2014-08-17
CVE-2014-3063 [HIGH] CWE-264 CVE-2014-3063: IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.
nvd
CVE-2014-0969P4MEDIUMCVSS 6.8v10.0v10.1+2 more2014-08-17
CVE-2014-0969 [MEDIUM] CWE-352 CVE-2014-0969: Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data M
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary
nvd
CVE-2020-4675P4MEDIUMCVSS 6.5v11.62021-07-16
CVE-2020-4675 [MEDIUM] CWE-352 CVE-2020-4675: IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which
IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
nvd
CVE-2016-9719P4MEDIUMCVSS 5.7v10.1v11.0+6 more2017-07-31
CVE-2016-9719 [MEDIUM] CWE-20 CVE-2016-9719: IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a re
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victi
nvd
CVE-2016-9718P4MEDIUMCVSS 5.4v10.1v11.0+6 more2017-07-31
CVE-2016-9718 [MEDIUM] CWE-79 CVE-2016-9718: IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.
nvd
CVE-2016-9715P4MEDIUMCVSS 5.4v11.0v11.3+4 more2017-07-31
CVE-2016-9715 [MEDIUM] CWE-79 CVE-2016-9715: IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.
nvd
CVE-2017-1199P4MEDIUMCVSS 5.4v10.1v11.0+6 more2017-08-03
CVE-2017-1199 [MEDIUM] CWE-79 CVE-2017-1199: IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.
nvd
CVE-2023-46187P4MEDIUMCVSS 5.4v11.6v12.0+2 more2025-01-27
CVE-2023-46187 [MEDIUM] CWE-79 CVE-2023-46187: IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site script
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2015-7423P4MEDIUMCVSS 5.4v9.1v10.1+3 more2018-03-26
CVE-2015-7423 [MEDIUM] CWE-79 CVE-2015-7423: Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) -
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.
nvd
CVE-2018-1380P4MEDIUMCVSS 4.9v11.4v11.5+1 more2018-10-29
CVE-2018-1380 [MEDIUM] CWE-200 CVE-2018-1380: IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authe
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.
nvd
CVE-2015-7414P4MEDIUMCVSS 5.4v9.1v10.1+3 more2016-01-17
CVE-2015-7414 [MEDIUM] CWE-79 CVE-2015-7414: Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Manageme
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4775P4MEDIUMCVSS 5.0v10.0v10.1+2 more2014-08-17
CVE-2014-4775 [MEDIUM] CWE-255 CVE-2014-4775: IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecif
nvd
CVE-2015-1984P4MEDIUMCVSS 4.0v9.1v10.1+3 more2015-07-20
CVE-2015-1984 [MEDIUM] CWE-200 CVE-2015-1984: IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before F
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
nvd
CVE-2015-7424P4MEDIUMCVSS 4.3v9.1v10.1+4 more2018-03-26
CVE-2015-7424 [MEDIUM] CWE-200 CVE-2015-7424: IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.
nvd
1 / 2Next →