cbcvebase.

Ibm Tivoli Netcool Omnibus Webgui vulnerabilities

12 known vulnerabilities affecting ibm/tivoli_netcool_omnibus_webgui.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM12

Vulnerabilities

Page 1 of 1
CVE-2021-29856P4MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29856 [MEDIUM] CVE-2021-29856: IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685.
nvd
CVE-2021-29820P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29820 [MEDIUM] CWE-79 CVE-2021-29820: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204347.
nvd
CVE-2021-29808P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29808 [MEDIUM] CWE-79 CVE-2021-29808: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cro IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204269.
nvd
CVE-2021-29807P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29807 [MEDIUM] CWE-79 CVE-2021-29807: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cro IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204265.
nvd
CVE-2021-29806P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29806 [MEDIUM] CWE-79 CVE-2021-29806: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cro IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204264.
nvd
CVE-2021-29819P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29819 [MEDIUM] CWE-79 CVE-2021-29819: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204346.
nvd
CVE-2021-29821P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29821 [MEDIUM] CWE-79 CVE-2021-29821: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204348.
nvd
CVE-2021-29818P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29818 [MEDIUM] CWE-79 CVE-2021-29818: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204345.
nvd
CVE-2021-29817P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29817 [MEDIUM] CWE-79 CVE-2021-29817: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204343.
nvd
CVE-2021-29809P4MEDIUMCVSS 5.4≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29809 [MEDIUM] CWE-79 CVE-2021-29809: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cro IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204270.
nvd
CVE-2021-20336P4MEDIUMCVSS 5.4v8.1.02021-03-11
CVE-2021-20336 [MEDIUM] CWE-79 CVE-2021-20336: IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerabilit IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-29811P4MEDIUMCVSS 4.9≥ 8.1.0, < 8.1.0.242021-09-20
CVE-2021-29811 [MEDIUM] CWE-522 CVE-2021-29811: IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.
nvd
Ibm Tivoli Netcool Omnibus Webgui vulnerabilities | cvebase