Infosphere Master Data Management Server

Vendor:

First CVE: Mar 16, 2014 · Active for 12 years

13
Total CVEs
More Total CVEs than 92% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Infosphere Master Data Management Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2014
12 years ago
Most Recent CVE
Jul 16, 2021
1,837 days ago

CVE Severity & Scoring

Infosphere Master Data Management Server13 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local1 (7.7%)
Network8 (61.5%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High0 (0.0%)
Unknown4 (30.8%)
User Interaction
None2 (15.4%)
Unknown4 (30.8%)
Required7 (53.8%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None3 (23.1%)
Unknown4 (30.8%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una
Jul 31, 20178.822NONO
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a
Jul 31, 20178.822NONO
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
Jul 19, 20177.819NONO
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c
Jul 31, 20175.418NONO
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM
Mar 16, 20146.818NONO
IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitte
Jul 16, 20216.517NONO
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presen
Jul 31, 20176.517NONO
Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated user
Jun 2, 20156.517NONO
IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
Aug 3, 20175.416NONO
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victi
Jul 31, 20175.716NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Infosphere Master Data Management Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.216.80.6%00
9.0.116.80.6%00
8.516.80.6%00
11.696.70.7%00
11.586.70.8%00
11.4106.50.8%00
11.3116.30.8%00
11.0116.30.8%00
10.196.00.9%00
10.016.80.6%00