Vulnerabilities > IBM > Infosphere Master Data Management > 11.0

DATE CVE VULNERABILITY TITLE RISK
2018-03-26 CVE-2015-7424 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access.
network
low complexity
ibm CWE-200
4.0
2018-03-26 CVE-2015-7423 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2016-01-17 CVE-2015-7414 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-01-17 CVE-2015-4960 7PK - Security Features vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
network
ibm CWE-254
3.5
2016-01-17 CVE-2015-4958 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.
local
low complexity
ibm CWE-200
2.1
2015-07-20 CVE-2015-1984 Permissions, Privileges, and Access Controls vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.
network
low complexity
ibm CWE-264
4.0
2015-07-20 CVE-2015-1982 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.
network
low complexity
ibm CWE-200
4.0
2015-07-20 CVE-2015-1980 Improper Input Validation vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
network
ibm CWE-20
3.5
2015-07-20 CVE-2015-1968 Cross-site Scripting vulnerability in IBM Infosphere Master Data Management
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2014-08-17 CVE-2014-4775 Credentials Management vulnerability in IBM products
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
ibm CWE-255
5.0