CVE-2017-1098
- EPSS 0.2%
- Veröffentlicht 07.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...
CVE-2016-6121
- EPSS 0.27%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...
CVE-2016-8949
- EPSS 0.12%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this ...
CVE-2017-1448
- EPSS 0.12%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this ...
CVE-2015-4939
- EPSS 0.24%
- Veröffentlicht 06.10.2015 01:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows rem...