Skip to main content

Vendor/product archive

ibm / emptoris_contract_management CVEs

Beta · best-effort

16 CVEs tagged to ibm / emptoris_contract_management2 Critical, 2 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2020-4892

Published Jan 7, 2021

IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1961

Published Apr 29, 2019

IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force ID: 153657.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6018

Published Jul 19, 2017

IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7398

Published Feb 15, 2016

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5050

Published Feb 15, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5042

Published Feb 15, 2016

IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 all…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3041

Published Aug 26, 2014

SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3034

Published Aug 26, 2014

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1