Vulnerabilities > IBM > Emptoris Strategic Supply Management > 10.0.1.0

DATE CVE VULNERABILITY TITLE RISK
2017-09-05 CVE-2017-1097 Cross-Site Request Forgery (CSRF) vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2017-08-14 CVE-2017-1190 Unspecified vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary code on the system.
local
high complexity
ibm
6.2
2017-08-14 CVE-2016-6029 Information Exposure vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
ibm CWE-200
4.3
2017-08-14 CVE-2016-6021 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-08-09 CVE-2017-1448 Open Redirect vulnerability in IBM products
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
4.9
2017-08-09 CVE-2016-8949 Open Redirect vulnerability in IBM products
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
ibm CWE-601
4.9
2017-08-09 CVE-2016-6121 Cross-site Scripting vulnerability in IBM products
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-13 CVE-2016-8952 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-07-13 CVE-2016-8951 Improper Authentication vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack.
network
low complexity
ibm CWE-287
5.0
2017-07-13 CVE-2016-6019 Cross-site Scripting vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5