Skip to main content

Vendor/product archive

ibm / campaign CVEs

Beta · best-effort

8 CVEs tagged to ibm / campaign0 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2018-1921

Published Jul 17, 2019

IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4384

Published Jun 19, 2019

IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1941

Published Dec 5, 2018

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9749

Published Nov 9, 2018

IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 12…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1115

Published Sep 7, 2018

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web brows…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1114

Published Sep 7, 2018

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1116

Published Apr 27, 2018

IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0265

Published Feb 1, 2017

IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-craf…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1