CVE-2016-8946
published 2017-07-12CVE-2016-8946: IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.73%
50.0th percentile
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118833.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c6q-xc5h-c242: IBM Emptoris Sourcing 9
ghsa_unreviewed·2022-05-17
CVE-2016-8946 [MEDIUM] CWE-79 GHSA-7c6q-xc5h-c242: IBM Emptoris Sourcing 9
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118833.
Red Hat
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
vendor_redhat·2016-07-06·CVSS 3.3
CVE-2016-6224 [LOW] CWE-200 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
bugzilla·2016-07-15·CVSS 3.3
CVE-2016-6224 [LOW] CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
CVE-2016-6224 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.
When GPT swap partitions are located on NVMe or MMC drives, ecryptfs-setup-swap fails to mark these swap partitions as "no-auto".
As a consequence, when using encrypted home directory with an NVMe or MMC drive, the swap is left unencrypted. There's also a usability issue in that users are erroneously prompted to enter a pass-phrase to unlock their swap partition at boot.
This vulnerability exists due to an incomplete fix for CVE-2015-8946
References:
http://seclists.org/oss-sec/2016/q3/52
Debian bug:
https://bugs.launchpad.net/ecryptfs
Bugzilla
CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
bugzilla·2016-07-15·CVSS 3.3
CVE-2015-8946 [LOW] CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
CVE-2015-8946 ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning
A vulnerability was found in ecryptfs-setup-swap script that is provided by the upstream ecryptfs-utils project.
On systems using systemd 211 or newer and GPT partitioning, the unencrypted swap partition was being automatically activated during boot and the encrypted swap was not used. This was due to ecryptfs-setup-swap not marking the swap partition as "no-auto", as defined by the Discoverable Partitions Spec.
References:
http://seclists.org/oss-sec/2016/q3/52
Debian bug:
https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/1447282
Fix:
https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/857
Discussion:
Created ecryptfs-utils tracking bugs for t
http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118833http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118833
2017-07-12
Published