CVE-2018-1875
- EPSS 0.14%
- Published 05.03.2019 18:29:00
- Last modified 21.11.2024 04:00:31
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit...
CVE-2018-1895
- EPSS 0.16%
- Published 15.02.2019 20:29:00
- Last modified 21.11.2024 04:00:33
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...
CVE-2018-1701
- EPSS 0.26%
- Published 15.02.2019 20:29:00
- Last modified 21.11.2024 04:00:13
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
CVE-2018-1518
- EPSS 0.01%
- Published 18.10.2018 15:29:00
- Last modified 21.11.2024 03:59:57
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
CVE-2017-1321
- EPSS 0.28%
- Published 12.07.2017 17:29:00
- Last modified 20.04.2025 01:37:25
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ...
CVE-2016-9000
- EPSS 0.24%
- Published 01.02.2017 22:59:01
- Last modified 20.04.2025 01:37:25
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attac...
CVE-2016-8999
- EPSS 0.27%
- Published 01.02.2017 22:59:01
- Last modified 20.04.2025 01:37:25
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
CVE-2016-6059
- EPSS 0.36%
- Published 01.02.2017 20:59:02
- Last modified 20.04.2025 01:37:25
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or cons...
CVE-2016-5984
- EPSS 0.21%
- Published 01.02.2017 20:59:01
- Last modified 20.04.2025 01:37:25
IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls....