CVE-2014-6212

3 documents3 sources
Severity
4.0MEDIUM
EPSS
0.2%
top 57.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 17

Description

The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allow

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages4 packages

NVDibm/emptorisstrategic_supply_management

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hj7c-xh4m-fm7w: The Echo API in IBM Emptoris Contract Management 92022-05-17
CVEList
CVE-2014-6212: The Echo API in IBM Emptoris Contract Management 92015-01-10