IBM / Filenet Content Manager
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-38366 | IBM FileNet Content Manager directory traversal | MEDIUM | 5.3 | Mar 1, 2024 |
| CVE-2023-47716 | IBM FileNet Content Manager privilege escalation | HIGH | 8.8 | Mar 1, 2024 |
| CVE-2023-35905 | IBM FileNet Content Manager cross-site scripting | MEDIUM | 5.4 | Oct 4, 2023 |
| CVE-2021-38965 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia… | HIGH | 8.8 | Jan 17, 2022 |
| CVE-2020-4759 | IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, cause… | HIGH | 7.8 | Nov 9, 2020 |
| CVE-2020-4447 | IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… | MEDIUM | 5.4 | Jul 23, 2020 |
| CVE-2019-4572 | IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an… | MEDIUM | 4.4 | Oct 14, 2019 |
| CVE-2018-1844 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp… | HIGH | 7.1 | Oct 12, 2018 |
| CVE-2018-1556 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… | MEDIUM | 5.4 | Jul 6, 2018 |
| CVE-2018-1555 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… | MEDIUM | 5.4 | Jul 6, 2018 |
| CVE-2018-1542 | IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vuln… | HIGH | 7.1 | Jul 6, 2018 |
| CVE-2016-8921 | IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable se… | HIGH | 8.8 | Feb 1, 2017 |
| CVE-2014-4763 | Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Fou… | LOW | 3.5 | Sep 15, 2014 |
| CVE-2013-6746 | Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manag… | MEDIUM | 4.3 | Jan 22, 2014 |
| CVE-2013-5449 | Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Co… | MEDIUM | 4.3 | Dec 4, 2013 |
| CVE-2010-3320 | Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sites and con… | MEDIUM | 6.8 | Sep 13, 2010 |
| CVE-2010-3319 | IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information b… | MEDIUM | 5.0 | Sep 13, 2010 |
| CVE-2010-3318 | IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by snif… | MEDIUM | 5.0 | Sep 13, 2010 |
| CVE-2010-3317 | Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or H… | MEDIUM | 4.3 | Sep 13, 2010 |
| CVE-2010-2896 | IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from… | MEDIUM | 4.3 | Jul 28, 2010 |
| CVE-2009-1953 | IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web… | MEDIUM | 4.6 | Jun 6, 2009 |
Showing 1 to 20 of 20 CVEs