CVE-2014-6212
IBM Emptoris Sourcing Portfolio - Authenticated XML External Entity Injection via Echo API
Title source: manualDescription
The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98689
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21693069
Scores
EPSS
0.0142
EPSS Percentile
70.0%
Details
Status
published
Products (37)
ibm/emptoris
strategic_supply_management 10.0.0.0 (14 CPE variants)
ibm/emptoris_contract_management
9.5.0.0
ibm/emptoris_contract_management
9.5.0.1
ibm/emptoris_contract_management
9.5.0.2
ibm/emptoris_contract_management
9.5.0.3
ibm/emptoris_contract_management
9.5.0.4
ibm/emptoris_contract_management
9.5.0.5
ibm/emptoris_contract_management
9.5.0.6
ibm/emptoris_contract_management
10.0.0.0
ibm/emptoris_contract_management
10.0.0.1
... and 27 more
Published
Jan 10, 2015
Tracked Since
Feb 18, 2026