CVE-2014-4790
published 2014-08-26CVE-2014-4790: IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend…
PriorityP421medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
0.80%
52.5th percentile
IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_sourcing_portfolio | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
| ibm | emptoris_spend_analysis | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gpqp-wqv8-8mph: IBM Emptoris Sourcing Portfolio 9
ghsa_unreviewed·2022-05-17
CVE-2014-4790 [MEDIUM] GHSA-gpqp-wqv8-8mph: IBM Emptoris Sourcing Portfolio 9
IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.
Red Hat
strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
vendor_redhat·2018-09-24·CVSS 5.0
CVE-2018-16152 [MEDIUM] CWE-287 strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
Package: strongimcv (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/60480http://secunia.com/advisories/60481http://www-01.ibm.com/support/docview.wss?uid=swg21680665http://www-01.ibm.com/support/docview.wss?uid=swg21681277https://exchange.xforce.ibmcloud.com/vulnerabilities/93195http://secunia.com/advisories/60480http://secunia.com/advisories/60481http://www-01.ibm.com/support/docview.wss?uid=swg21680665http://www-01.ibm.com/support/docview.wss?uid=swg21681277https://exchange.xforce.ibmcloud.com/vulnerabilities/93195
2014-08-26
Published