← Back

CVE-2014-6212

nvd nist
Published: Jan 10, 2015Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected (63)

4 products
Emptoris Sourcing Portfolio
Emptoris Program Management
Emptoris Contract Management
Emptoris
Configuration A
17 vulnerable
Configuration B
14 vulnerable
Configuration C
18 vulnerable
Configuration D
14 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version strategic_supply_management 10.0.0.0
Version strategic_supply_management 10.0.0.1
Version strategic_supply_management 10.0.0.2
Version strategic_supply_management 10.0.0.3
Version strategic_supply_management 10.0.1.0
Version strategic_supply_management 10.0.1.1
Version strategic_supply_management 10.0.1.2
Version strategic_supply_management 10.0.1.3
Version strategic_supply_management 10.0.1.4
Version strategic_supply_management 10.0.2.0
Version strategic_supply_management 10.0.2.1
Version strategic_supply_management 10.0.2.2
Version strategic_supply_management 10.0.2.3
Version strategic_supply_management 10.0.2.4

References (4)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.