CVE-2014-6212

IBM Emptoris Sourcing Portfolio - Authenticated XML External Entity Injection via Echo API

Title source: manual
STIX 2.1

Description

The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98689
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21693069

Scores

EPSS 0.0142
EPSS Percentile 70.0%

Details

Status published
Products (37)
ibm/emptoris strategic_supply_management 10.0.0.0 (14 CPE variants)
ibm/emptoris_contract_management 9.5.0.0
ibm/emptoris_contract_management 9.5.0.1
ibm/emptoris_contract_management 9.5.0.2
ibm/emptoris_contract_management 9.5.0.3
ibm/emptoris_contract_management 9.5.0.4
ibm/emptoris_contract_management 9.5.0.5
ibm/emptoris_contract_management 9.5.0.6
ibm/emptoris_contract_management 10.0.0.0
ibm/emptoris_contract_management 10.0.0.1
... and 27 more
Published Jan 10, 2015
Tracked Since Feb 18, 2026