VendorsIBMmarketing_platform9.1.0.0
Vulnerabilities

IBM Marketing Platform 9.1.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2016-0224
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2016-06-28 · Modified
9.8EPSS 0.013
CVE-2016-0233
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2016-06-28 · Modified
8.8EPSS 0.011
CVE-2016-6112
IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282.
Published 2017-05-22 · Modified
8.8EPSS 0.010
CVE-2013-6311
SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2014-06-28 · Modified
6.5EPSS 0.010
CVE-2016-0229
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2016-06-28 · Modified
6.1EPSS 0.008
CVE-2013-6309
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.
Published 2014-06-28 · Modified
6.0EPSS 0.009
CVE-2013-6308
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection.
Published 2014-06-28 · Modified
4.9EPSS 0.009
CVE-2017-1107
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.
Published 2019-06-19 · Modified
4.3EPSS 0.014
CVE-2013-6310
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-06-28 · Modified
3.5EPSS 0.008