Vulnerabilities > IBM > Infosphere Master Data Management

DATE CVE VULNERABILITY TITLE RISK
2018-10-29 CVE-2018-1380 Information Exposure vulnerability in IBM Infosphere Master Data Management 11.4/11.5/11.6
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information.
network
low complexity
ibm CWE-200
4.0
2018-03-26 CVE-2015-7424 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access.
network
low complexity
ibm CWE-200
4.0
2018-03-26 CVE-2015-7423 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2017-10-24 CVE-2017-1523 Missing Authentication for Critical Function vulnerability in IBM Infosphere Master Data Management 11.5
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication.
network
low complexity
ibm CWE-306
5.0
2016-01-17 CVE-2015-7414 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-01-17 CVE-2015-4960 7PK - Security Features vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
network
ibm CWE-254
3.5
2016-01-17 CVE-2015-4958 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.
local
low complexity
ibm CWE-200
2.1
2015-07-20 CVE-2015-1984 Permissions, Privileges, and Access Controls vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
network
low complexity
ibm CWE-264
4.0
2015-07-20 CVE-2015-1982 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.
network
low complexity
ibm CWE-200
4.0
2015-07-20 CVE-2015-1980 Improper Input Validation vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
network
ibm CWE-20
3.5