4

CVE-2015-5024

IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Emptoris Sourcing Version 10.0.2.0
Ibm ≫ Emptoris Sourcing Version 10.0.2.2
Ibm ≫ Emptoris Sourcing Version 10.0.2.3
Ibm ≫ Emptoris Sourcing Version 10.0.2.5
Ibm ≫ Emptoris Sourcing Version 10.0.2.6
Ibm ≫ Emptoris Sourcing Version 10.0.2.7
Ibm ≫ Emptoris Sourcing Version 10.0.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.97% 0.571
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www-01.ibm.com/support/docview.wss?uid=swg21967255
Patch
Vendor Advisory