Ibm Infosphere Master Data Management Collaboration Server vulnerabilities
10 known vulnerabilities affecting ibm/infosphere_master_data_management_collaboration_server.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5LOW5
Vulnerabilities
Page 1 of 1
CVE-2018-1380MEDIUMCVSS 4.9v11.4v11.5+1 more2018-10-29
CVE-2018-1380 [LOW] CWE-200 CVE-2018-1380: IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authe
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.
cvelistv5nvd
CVE-2014-3064MEDIUMCVSS 6.3v10.0v10.1+1 more2014-07-19
CVE-2014-3064 [MEDIUM] CWE-200 CVE-2014-3064: The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x bef
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.
nvd
CVE-2014-0968LOWCVSS 3.5v10.0v10.1+1 more2014-07-19
CVE-2014-0968 [LOW] CWE-79 CVE-2014-0968: Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Manageme
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL for an MHTML docu
nvd
CVE-2014-0967LOWCVSS 3.5v10.0v10.1+1 more2014-07-19
CVE-2014-0967 [LOW] CWE-79 CVE-2014-0967: Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Manageme
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-0970LOWCVSS 3.5v10.0v10.1+1 more2014-07-19
CVE-2014-0970 [LOW] CWE-20 CVE-2014-0970: The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x bef
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors.
nvd
CVE-2013-5427MEDIUMCVSS 6.8v10.0v10.1+1 more2014-02-04
CVE-2013-5427 [MEDIUM] CWE-352 CVE-2013-5427: Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collabora
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users.
nvd
CVE-2013-5426MEDIUMCVSS 4.9v10.0v10.1+1 more2013-12-19
CVE-2013-5426 [MEDIUM] CWE-287 CVE-2013-5426: Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.
nvd
CVE-2013-4036LOWCVSS 3.5v10.0v10.1+1 more2013-11-27
CVE-2013-4036 [LOW] CWE-79 CVE-2013-4036: Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0477MEDIUMCVSS 6.0v10.0.0v10.0.12013-02-21
CVE-2013-0477 [MEDIUM] CWE-79 CVE-2013-0477: Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Colla
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
nvd
CVE-2013-0478LOWCVSS 3.5v10.0.0v10.0.12013-02-21
CVE-2013-0478 [LOW] CWE-79 CVE-2013-0478: Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Ed
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd