Lucene search

K
cveIbmCVE-2015-0146
HistoryMar 18, 2015 - 10:59 a.m.

CVE-2015-0146

2015-03-1810:59:06
CWE-264
ibm
web.nvd.nist.gov
30
ibm
content collector
email
vulnerability
ibm content search services
ibm filenet p8
sensitive information
search query

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

Affected configurations

Nvd
Node
ibmcontent_collectorMatch3.0.0.0
OR
ibmcontent_collectorMatch3.0.0.1
OR
ibmcontent_collectorMatch3.0.0.2
OR
ibmcontent_collectorMatch3.0.0.3
OR
ibmcontent_collectorMatch3.0.0.4
OR
ibmcontent_collectorMatch3.0.0.5
OR
ibmcontent_collectorMatch4.0.0.0
OR
ibmcontent_collectorMatch4.0.0.1
OR
ibmcontent_collectorMatch4.0.0.2
VendorProductVersionCPE
ibmcontent_collector3.0.0.0cpe:2.3:a:ibm:content_collector:3.0.0.0:*:*:*:*:*:*:*
ibmcontent_collector3.0.0.1cpe:2.3:a:ibm:content_collector:3.0.0.1:*:*:*:*:*:*:*
ibmcontent_collector3.0.0.2cpe:2.3:a:ibm:content_collector:3.0.0.2:*:*:*:*:*:*:*
ibmcontent_collector3.0.0.3cpe:2.3:a:ibm:content_collector:3.0.0.3:*:*:*:*:*:*:*
ibmcontent_collector3.0.0.4cpe:2.3:a:ibm:content_collector:3.0.0.4:*:*:*:*:*:*:*
ibmcontent_collector3.0.0.5cpe:2.3:a:ibm:content_collector:3.0.0.5:*:*:*:*:*:*:*
ibmcontent_collector4.0.0.0cpe:2.3:a:ibm:content_collector:4.0.0.0:*:*:*:*:*:*:*
ibmcontent_collector4.0.0.1cpe:2.3:a:ibm:content_collector:4.0.0.1:*:*:*:*:*:*:*
ibmcontent_collector4.0.0.2cpe:2.3:a:ibm:content_collector:4.0.0.2:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2015-0146