Vulnerabilities > IBM > Infosphere Datastage

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-9000 Cross-site Scripting vulnerability in IBM products
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection.
network
low complexity
ibm CWE-79
6.1
2017-02-01 CVE-2016-8999 Cross-site Scripting vulnerability in IBM products
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
network
low complexity
ibm CWE-79
5.4
2017-02-01 CVE-2016-8982 Information Exposure vulnerability in IBM Infosphere Datastage 11.3/8.7/9.1
IBM InfoSphere Information Server stores sensitive information in URL parameters.
network
low complexity
ibm CWE-200
5.3
2017-02-01 CVE-2016-6059 XXE vulnerability in IBM products
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
8.1