Vulnerability CVE-2016-6019


Published: 2017-07-13

Description:
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.

Vendor: IBM
Product: Emptoris strategic supply management 
Version:
10.1.1.9
10.1.1.8
10.1.1.7
10.1.1.6
10.1.1.5
10.1.1.4
10.1.1.3
10.1.1.2
10.1.1.10
10.1.1.1
10.1.1.0
10.1.0.9
10.1.0.8
10.1.0.7
10.1.0.6
10.1.0.5
10.1.0.4
10.1.0.3
10.1.0.2
10.1.0.12
10.1.0.11
10.1.0.10
10.1.0.1
10.1.0.0
10.0.4.0
10.0.2.9
10.0.2.8
10.0.2.7
10.0.2.6
10.0.2.5
10.0.2.4
10.0.2.3
10.0.2.2
10.0.2.17
10.0.2.16
10.0.2.15
10.0.2.14
10.0.2.13
10.0.2.12
10.0.2.11
10.0.2.10
10.0.2.1
10.0.2.0
10.0.1.4
10.0.1.3
10.0.1.2
10.0.1.1
10.0.1.0
10.0.0.3
10.0.0.2
10.0.0.1
10.0.0.0

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://www.ibm.com/support/docview.wss?uid=swg22005839
http://www.securityfocus.com/bid/99589
https://exchange.xforce.ibmcloud.com/vulnerabilities/116739

Related CVE
CVE-2016-0342
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783.
CVE-2016-0329
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirec...
CVE-2016-0312
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486.
CVE-2016-0311
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Forc...
CVE-2016-0303
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-0300
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412.
CVE-2017-1773
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
CVE-2017-1233
IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.

Copyright 2018, cxsecurity.com

 

Back to Top