2.1

CVE-2015-0146

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

Data is provided by the National Vulnerability Database (NVD)
IbmContent Collector Version3.0.0.0
IbmContent Collector Version3.0.0.1
IbmContent Collector Version3.0.0.2
IbmContent Collector Version3.0.0.3
IbmContent Collector Version3.0.0.4
IbmContent Collector Version3.0.0.5
IbmContent Collector Version4.0.0.0
IbmContent Collector Version4.0.0.1
IbmContent Collector Version4.0.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.125
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N