Vulnerabilities > IBM > Emptoris Sourcing > 10.0.2.2

DATE CVE VULNERABILITY TITLE RISK
2018-02-02 CVE-2016-0329 Open Redirect vulnerability in IBM Emptoris Sourcing
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-601
4.9
2015-10-06 CVE-2015-5024 Information Exposure vulnerability in IBM Emptoris Sourcing
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.
network
low complexity
ibm CWE-200
4.0