cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2018-1380,https://securityvulnerability.io/vulnerability/CVE-2018-1380,,"IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.",IBM,Infosphere Master Data Management Collaboration Server,2.7,LOW,0.0006500000017695129,false,,false,false,false,,,false,false,,2018-10-29T15:29:00.000Z,0 CVE-2015-1945,https://securityvulnerability.io/vulnerability/CVE-2015-1945,,"Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors.",IBM,Infosphere Master Data Management Server,,,0.0019199999514967203,false,,false,false,false,,,false,false,,2015-06-02T14:00:00.000Z,0 CVE-2015-1910,https://securityvulnerability.io/vulnerability/CVE-2015-1910,,"Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.",IBM,Infosphere Master Data Management Server,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2015-05-25T00:00:00.000Z,0 CVE-2015-1909,https://securityvulnerability.io/vulnerability/CVE-2015-1909,,"The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.",IBM,Infosphere Master Data Management Server,,,0.0020600000862032175,false,,false,false,false,,,false,false,,2015-05-25T00:00:00.000Z,0 CVE-2014-8899,https://securityvulnerability.io/vulnerability/CVE-2014-8899,,"Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8898.",IBM,Infosphere Master Data Management Collaborative Server,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-12-22T16:00:00.000Z,0 CVE-2014-8897,https://securityvulnerability.io/vulnerability/CVE-2014-8897,,"Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8898 and CVE-2014-8899.",IBM,Infosphere Master Data Management Collaborative Server,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-12-22T16:00:00.000Z,0 CVE-2014-8896,https://securityvulnerability.io/vulnerability/CVE-2014-8896,,"The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors.",IBM,Infosphere Master Data Management Server For Product Information Management,,,0.0007900000200606883,false,,false,false,false,,,false,false,,2014-12-22T16:00:00.000Z,0 CVE-2014-8898,https://securityvulnerability.io/vulnerability/CVE-2014-8898,,"Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8897 and CVE-2014-8899.",IBM,Infosphere Master Data Management Collaborative Server,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-12-22T16:00:00.000Z,0 CVE-2014-4775,https://securityvulnerability.io/vulnerability/CVE-2014-4775,,"IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.",IBM,"Infosphere Master Data Management,Infosphere Master Data Management Server For Product Information Management",,,0.0037700000684708357,false,,false,false,false,,,false,false,,2014-08-17T23:55:00.000Z,0 CVE-2014-3063,https://securityvulnerability.io/vulnerability/CVE-2014-3063,,IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management",,,0.0004199999966658652,false,,false,false,false,,,false,false,,2014-08-17T23:55:00.000Z,0 CVE-2014-0966,https://securityvulnerability.io/vulnerability/CVE-2014-0966,,SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management",,,0.0026400000788271427,false,,false,false,false,,,false,false,,2014-08-17T23:55:00.000Z,0 CVE-2014-0969,https://securityvulnerability.io/vulnerability/CVE-2014-0969,,Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management",,,0.0027000000700354576,false,,false,false,false,,,false,false,,2014-08-17T23:55:00.000Z,0 CVE-2014-3009,https://securityvulnerability.io/vulnerability/CVE-2014-3009,,"The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.",IBM,Infosphere Master Data Management Server For Product Information Management,,,0.0006799999973736703,false,,false,false,false,,,false,false,,2014-08-01T01:00:00.000Z,0 CVE-2014-0967,https://securityvulnerability.io/vulnerability/CVE-2014-0967,,Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-07-19T01:00:00.000Z,0 CVE-2014-0968,https://securityvulnerability.io/vulnerability/CVE-2014-0968,,Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL for an MHTML document.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-07-19T01:00:00.000Z,0 CVE-2014-0970,https://securityvulnerability.io/vulnerability/CVE-2014-0970,,The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to inject links via unspecified vectors.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0007900000200606883,false,,false,false,false,,,false,false,,2014-07-19T01:00:00.000Z,0 CVE-2014-3064,https://securityvulnerability.io/vulnerability/CVE-2014-3064,,The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0011899999808520079,false,,false,false,false,,,false,false,,2014-07-19T01:00:00.000Z,0 CVE-2014-0873,https://securityvulnerability.io/vulnerability/CVE-2014-0873,,"Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users.",IBM,Infosphere Master Data Management Server,,,0.0008999999845400453,false,,false,false,false,,,false,false,,2014-03-16T10:00:00.000Z,0 CVE-2013-5427,https://securityvulnerability.io/vulnerability/CVE-2013-5427,,Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0008999999845400453,false,,false,false,false,,,false,false,,2014-02-04T02:00:00.000Z,0 CVE-2013-5426,https://securityvulnerability.io/vulnerability/CVE-2013-5426,,Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.,IBM,"Infosphere Master Data Management Server For Product Information Management,Infosphere Master Data Management Collaboration Server",,,0.0010400000028312206,false,,false,false,false,,,false,false,,2013-12-19T22:00:00.000Z,0 CVE-2013-4036,https://securityvulnerability.io/vulnerability/CVE-2013-4036,,"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.",IBM,Infosphere Master Data Management Server For Product Information Management,,,0.0006200000061653554,false,,false,false,false,,,false,false,,2013-11-27T02:00:00.000Z,0 CVE-2013-0478,https://securityvulnerability.io/vulnerability/CVE-2013-0478,,"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.",IBM,Infosphere Master Data Management Collaboration Server,,,0.0006200000061653554,false,,false,false,false,,,false,false,,2013-02-21T01:00:00.000Z,0 CVE-2013-0477,https://securityvulnerability.io/vulnerability/CVE-2013-0477,,"Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.",IBM,Infosphere Master Data Management Collaboration Server,,,0.0015399999683722854,false,,false,false,false,,,false,false,,2013-02-21T01:00:00.000Z,0