CVE-2014-4790
Published Aug 26, 2014
Last updated 7 years ago
Overview
- Description
- IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.9
- Impact score
- 4.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1173E8F6-A85E-452C-9B36-89427D57DDF0" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD21D4C5-5180-4AE0-A11F-009A6CF1EFA0" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EC42DEB-FA8D-42C4-ACDC-0A5036939B2E" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE122AF0-070A-41EE-980C-C55BF1A7995F" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "501E457B-084A-4E3B-981A-01B19B28B0B1" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54F1BCFD-6DCD-4427-AC89-638588878713" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C2FD0BD-DFFF-4512-A290-EACBC82EFB04" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "251FE42A-D7C2-415A-8356-F0B1A141147A" }, { "criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A975908E-A3C9-4F2C-AE37-66F6F54239DA" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "516752F7-FBA1-4A6B-9BFB-B266024AEBD4" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C6D86CF-6DCD-4B23-AA59-77780D9F141E" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9AE02CB-CD39-4A88-8F9E-AFCDFBB9025F" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9AE268C-C2B0-4FC6-BC81-E1A34F95709E" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81CAB980-749B-4573-8C2E-A3C4E1313CC0" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:9.5.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69D4F224-F077-4C59-B76E-76A41F829B74" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E67AA9E6-8E05-4EA6-99ED-51C7F5D11501" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E34A7ACD-EF0D-4333-A3A0-8CE4CB132FF7" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5820700D-1124-4BF3-ABF5-AD6271D2480C" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8BC7A60-CF57-48BA-BDAF-C995E1FFF30F" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37DB7389-8FF9-4E94-BD94-9685E6AADAEE" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "162FE448-69CA-45B7-A902-A5F3A9966D8A" }, { "criteria": "cpe:2.3:a:ibm:emptoris_sourcing_portfolio:10.0.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6C9636B-D48A-4836-9679-A6E197FB35CB" } ], "operator": "OR" } ] } ]