3.5
CVSSv2

CVE-2015-4971

Published: 06/10/2015 Updated: 06/10/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x prior to 10.0.1.4_iFix3, 10.0.2.x prior to 10.0.2.7_iFix1, 10.0.3.x prior to 10.0.3.2, and 10.0.4.x prior to 10.0.4.0_iFix1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm emptoris supplier_lifecycle_management

ibm emptoris strategic_supply_management

ibm emptoris program management 10.0.1.0

ibm emptoris program management 10.0.0.3

ibm emptoris program management 10.0.0.2

ibm emptoris program management 10.0.0.1

ibm emptoris program management 10.0.2.7

ibm emptoris program management 10.0.2.5

ibm emptoris program management 10.0.1.3

ibm emptoris program management 10.0.1.1

ibm emptoris program management 10.0.0.0

ibm emptoris program management 10.0.2.3

ibm emptoris program management 10.0.2.2

ibm emptoris program management 10.0.2.1

ibm emptoris program management 10.0.2.0

ibm emptoris program management 10.0.2.6

ibm emptoris program management 10.0.2.4

ibm emptoris program management 10.0.1.4

ibm emptoris program management 10.0.1.2