Infosphere Master Data Management

Vendor:

First CVE: Aug 1, 2014 · Active for 11 years

17
Total CVEs
More Total CVEs than 94% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Infosphere Master Data Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2014
11 years ago
Most Recent CVE
Jan 27, 2025
547 days ago

CVE Severity & Scoring

Infosphere Master Data Management17 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local1 (5.9%)
Network7 (41.2%)
Unknown9 (52.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (47.1%)
High0 (0.0%)
Unknown9 (52.9%)
User Interaction
None4 (23.5%)
Unknown9 (52.9%)
Required4 (23.5%)
Privileges Required
Low6 (35.3%)
High1 (5.9%)
None1 (5.9%)
Unknown9 (52.9%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
Oct 24, 20177.525NONO
IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Ma
Aug 17, 20147.523NONO
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users
Oct 29, 20184.919NONO
Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.
Jan 17, 20165.419NONO
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W
Jan 27, 20255.418NONO
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere M
Aug 17, 20146.818NONO
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticate
Mar 26, 20185.417NONO
SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Managemen
Aug 17, 20146.517NONO
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management
Aug 1, 20143.516NONO
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions an
Mar 26, 20184.315NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Infosphere Master Data Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.194.20.8%00
14.015.40.3%00
12.015.40.3%00
11.625.20.7%00
11.535.61.5%00
11.4104.20.9%00
11.3134.90.9%00
11.0144.80.9%00
10.1144.80.9%00
10.055.91.0%00