Lucene search

K
cveIbmCVE-2014-6212
HistoryJan 10, 2015 - 2:59 a.m.

CVE-2014-6212

2015-01-1002:59:28
ibm
web.nvd.nist.gov
24
cve-2014-6212
ibm emptoris
xxe
remote code execution
security vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

44.4%

The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected configurations

Nvd
Node
ibmemptoris_sourcing_portfolioMatch9.5.0.0
OR
ibmemptoris_sourcing_portfolioMatch9.5.0.1
OR
ibmemptoris_sourcing_portfolioMatch9.5.0.2
OR
ibmemptoris_sourcing_portfolioMatch9.5.1.0
OR
ibmemptoris_sourcing_portfolioMatch9.5.1.1
OR
ibmemptoris_sourcing_portfolioMatch9.5.1.2
OR
ibmemptoris_sourcing_portfolioMatch9.5.1.3
OR
ibmemptoris_sourcing_portfolioMatch10.0.0.0
OR
ibmemptoris_sourcing_portfolioMatch10.0.0.1
OR
ibmemptoris_sourcing_portfolioMatch10.0.1.0
OR
ibmemptoris_sourcing_portfolioMatch10.0.1.1
OR
ibmemptoris_sourcing_portfolioMatch10.0.1.2
OR
ibmemptoris_sourcing_portfolioMatch10.0.1.3
OR
ibmemptoris_sourcing_portfolioMatch10.0.2.0
OR
ibmemptoris_sourcing_portfolioMatch10.0.2.2
OR
ibmemptoris_sourcing_portfolioMatch10.0.2.3
OR
ibmemptoris_sourcing_portfolioMatch10.0.2.4
Node
ibmemptoris_program_managementMatch10.0.0.0
OR
ibmemptoris_program_managementMatch10.0.0.1
OR
ibmemptoris_program_managementMatch10.0.0.2
OR
ibmemptoris_program_managementMatch10.0.0.3
OR
ibmemptoris_program_managementMatch10.0.1.0
OR
ibmemptoris_program_managementMatch10.0.1.1
OR
ibmemptoris_program_managementMatch10.0.1.2
OR
ibmemptoris_program_managementMatch10.0.1.3
OR
ibmemptoris_program_managementMatch10.0.1.4
OR
ibmemptoris_program_managementMatch10.0.2.0
OR
ibmemptoris_program_managementMatch10.0.2.1
OR
ibmemptoris_program_managementMatch10.0.2.2
OR
ibmemptoris_program_managementMatch10.0.2.3
OR
ibmemptoris_program_managementMatch10.0.2.4
Node
ibmemptoris_contract_managementMatch9.5.0.0
OR
ibmemptoris_contract_managementMatch9.5.0.1
OR
ibmemptoris_contract_managementMatch9.5.0.2
OR
ibmemptoris_contract_managementMatch9.5.0.3
OR
ibmemptoris_contract_managementMatch9.5.0.4
OR
ibmemptoris_contract_managementMatch9.5.0.5
OR
ibmemptoris_contract_managementMatch9.5.0.6
OR
ibmemptoris_contract_managementMatch10.0.0.0
OR
ibmemptoris_contract_managementMatch10.0.0.1
OR
ibmemptoris_contract_managementMatch10.0.1.0
OR
ibmemptoris_contract_managementMatch10.0.1.1
OR
ibmemptoris_contract_managementMatch10.0.1.2
OR
ibmemptoris_contract_managementMatch10.0.1.3
OR
ibmemptoris_contract_managementMatch10.0.1.4
OR
ibmemptoris_contract_managementMatch10.0.1.5
OR
ibmemptoris_contract_managementMatch10.0.2.0
OR
ibmemptoris_contract_managementMatch10.0.2.1
OR
ibmemptoris_contract_managementMatch10.0.2.2
Node
ibmemptorisMatchstrategic_supply_management10.0.0.0
OR
ibmemptorisMatchstrategic_supply_management10.0.0.1
OR
ibmemptorisMatchstrategic_supply_management10.0.0.2
OR
ibmemptorisMatchstrategic_supply_management10.0.0.3
OR
ibmemptorisMatchstrategic_supply_management10.0.1.0
OR
ibmemptorisMatchstrategic_supply_management10.0.1.1
OR
ibmemptorisMatchstrategic_supply_management10.0.1.2
OR
ibmemptorisMatchstrategic_supply_management10.0.1.3
OR
ibmemptorisMatchstrategic_supply_management10.0.1.4
OR
ibmemptorisMatchstrategic_supply_management10.0.2.0
OR
ibmemptorisMatchstrategic_supply_management10.0.2.1
OR
ibmemptorisMatchstrategic_supply_management10.0.2.2
OR
ibmemptorisMatchstrategic_supply_management10.0.2.3
OR
ibmemptorisMatchstrategic_supply_management10.0.2.4
VendorProductVersionCPE
ibmemptoris_sourcing_portfolio9.5.0.0cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.0:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.0.1cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.1:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.0.2cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.2:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.1.0cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.0:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.1.1cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.1:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.1.2cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.2:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio9.5.1.3cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.3:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio10.0.0.0cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.0.0:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio10.0.0.1cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.0.1:*:*:*:*:*:*:*
ibmemptoris_sourcing_portfolio10.0.1.0cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.1.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 631

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

44.4%

Related for CVE-2014-6212